This page contains the DigiCert dedicated IP addresses for DigiCert Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), and a few other DigiCert services.
How do these IP addresses affect my digital certificate environment?
DigiCert certificate status IPv4 addresses
DigiCert certificate status IPv6 addresses
DigiCert adding new dedicated IPv4 addresses On September 8, 2025, at 08:00 MST (15:00 UTC), DigiCert will add a secondary CDN (content delivery network) and assign additional IPv4 addresses to our Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), and a few other DigiCert services. If your company uses allowlists to control outbound traffic, update your outbound allowlist on your firewalls, security groups, or proxies to include the new IPv4 addresses below before September 8, 2025. You must do this to keep your DigiCert services running as they were before the addition of the new IPv4 addresses.
|
|
|
|
To learn more, see our change log entry for September 8, 2025, DigiCert: Adding a secondary CDN with additional dedicated IP addresses. |
Do you have DigiCert certificates? Do you use allowlists to control inbound and outbound connectivity to your environment?
Then, check the table below and add the necessary IPv4 addresses to your allowlist. You must allow outbound connectivity to these addresses to verify if a certificate should be trusted.
OCSP and CRL distribution endpoints using any of the following subdomains do not use the IPv4 addresses in the table below:
DigiCert ONE: If your Trust Lifecycle, Software Trust, or Document Trust Manager (USA, CH, NL, JP) uses public certificates from CertCentral Global, CertCentral Europe, or PKI Platform 8, you may want to add these IPv4 addresses to your allowlist.
What are OCSPs and CRLs used for?
Your applications and browsers call one of our OCSP or CRL endpoints to learn the revocation status of a DigiCert certificate, such as a TLS or code signing certificate.
Most of the IPv4 addresses are for the DigiCert OCSPs and CRLs. However, we have included some additional PKI Platform 8 services in the table.
Service | URL | IPv4 addresses |
CertCentral Global OCSPs |
|
|
CertCentral Global CRLs |
|
See CertCentral Global OCSPs |
CertCentral Europe OCSPs |
|
|
CertCentral Europe CRLs |
|
See CertCentral Europe OCSPs |
CertCentral Europe CA certificates |
|
See CertCentral Europe OCSPs |
PKI Platform 8 OCSP |
|
|
PKI Platform 8 CRL/CA certificates |
|
See CertCentral Global OCSPs |
PKI client downloads |
|
See CertCentral Global OCSPs |
QuoVadis TrustLink OCSP |
|
|
On January 10, 2025, we are moving to a CDN (content delivery network). Unfortunately, we must remove support for IPv6 addresses.