This page contains the DigiCert dedicated IP addresses for DigiCert Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), and a few other DigiCert services.
Most of the IP addresses are for the CertCentral OCSPs and CRLs. However, we have included some additional PKI Platform 8 and QuoVadis CLRs and OCSPs in the table.
How do these IP addresses affect my digital certificate environment?
DigiCert certificate status IPv4 addresses
DigiCert certificate status IPv6 addresses
DigiCert is adding new dedicated IPv4 addresses and assigning new dedicated IPv6 addresses |
|
On March 10, 2026, at 10:00 MDT (16:00 UTC), DigiCert will add new IPv4 addresses and assign dedicated IPv6 addresses to our Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), and a few other DigiCert services. If your company uses allowlists to control outbound traffic, update your outbound allowlist on your firewalls, security groups, or proxies to include the new IPv4 and IPv6 addresses below before March 10, 2026. You must do this to keep your DigiCert services running as they were before the addition of the new IPv4 and IPv6 addresses. Note: If your company supports or plans to support IPv6 addresses, you must add them to your allowlist.
|
|
| IPv4 addresses | IPv6 addresses |
|
|
Do you have DigiCert certificates, such as TLS certificates? Do you use allowlists to control inbound and outbound connectivity to your environment?
Then, check the table below and add the necessary IPv4 and IPv6 addresses to your allowlist. You must allow outbound connectivity to these addresses to verify if a certificate should be trusted.
OCSP and CRL distribution endpoints using any of the following subdomains do not use the IPv4 or IPv6 addresses in the table below:
DigiCert ONE: If your Trust Lifecycle, Software Trust, or Document Trust Manager (USA, CH, NL, AU, JP) uses public certificates from CertCentral Global, CertCentral Europe, or PKI Platform 8, you may want to add these IPv4 and IPv6 addresses to your allowlist.
What are OCSPs and CRLs used for?
Your applications and browsers call one of our OCSP or CRL endpoints to learn the revocation status of a DigiCert certificate, such as a TLS or code signing certificate.
Most of the IPv4 addresses are for the DigiCert OCSPs and CRLs. However, we have included some additional PKI Platform 8 and QuoVadis CLRs and OCSPs in the table.
| Service | URL | IPv4 addresses |
| CertCentral Global OCSPs |
|
|
| CertCentral Global CRLs |
|
See CertCentral Global OCSPs |
| CertCentral Europe OCSPs |
|
|
| CertCentral Europe CRLs |
|
See CertCentral Europe OCSPs |
| CertCentral Europe CA certificates |
|
See CertCentral Europe OCSPs |
| PKI Platform 8 OCSP |
|
|
| PKI Platform 8 CRL/CA certificates |
|
See CertCentral Global OCSPs |
| PKI client downloads |
|
See CertCentral Global OCSPs |
| QuoVadis TrustLink OCSP |
|
|
Most of the IPv6 addresses are for the DigiCert OCSPs and CRLs. However, we have included some additional PKI Platform 8 and QuoVadis CLRs and OCSPs in the table.
| Service | URL | IPv4 addresses |
| CertCentral Global OCSPs |
|
|
| CertCentral Global CRLs |
|
|
| CertCentral Europe OCSPs |
|
|
| CertCentral Europe CRLs |
|
|
| CertCentral Europe CA certificates |
|
|
| PKI Platform 8 OCSP |
|
|
| PKI Platform 8 CRL/CA certificates |
|
|
| PKI client downloads |
|
|
| PKI client downloads |
|