“The Chrome distrusts of GLOBALTRUST and Entrust were both implemented using SCTNotAfter.”

Chrome now distrusts a bad CA by the issue date recorded in the transparency logs. Existing certificates keep working until they expire, and the CA cannot backdate new ones. Users see no errors at all. The 2017 Symantec distrust broke sites everywhere.