thanks for all the insights
but that is not the problem. firefox able to connect to google services with all other certificates disabled by enabling the old deprecated certificate chain (the signing root is not the same globalsign entity). but this happens only with the macos in the sense that i am not able to connect to google services with latest certificates.
maybe i share more of the concerns to help with understanding: i captured in the wild a non google website (ip address owner not google) but posing as xxxxxxxx.gvt1.com which passes through application firewall because reverse dns check only checked for matches to *.gvt1.com that website has a certificate signed by a legitimate root ca (not gts or globalsign). so, i have grown very cautius about checking certificates validity.
after all, why would google deprecate a non expiring certificate ?
i use apple devices extensively but a very concerned about security but i am not technical profession and appreciate any and all insights.
maybe i share another finding as an end user :
in mac os network settings for all interfaces, on the proxy tab, there are built-in ecxceptions of localhost, 169.254.* which i understand should be private addresses, that is, not sent to outside internet, but if i try to check by command route get 169.254.1.1 (when i am connected to internet), 169.254.1.1 goes through default gateway out of the device. traceroute would show similar results. so, it is possible to send from 169.254.1.1 to my computer and reply bypassing the application firewall (lulu, little snitch) or packet filter (incl. murus) because it runs as an exeption to the proxy at the interface ?
as an end user wishing to use apple notebooks, therefore, am very sensitive as to last resort of https.
thanks for understanding