This page contains the DigiCert dedicated IP addresses for DigiCert Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), and a few other DigiCert services.
How do these IP addresses affect my digital certificate environment?
DigiCert certificate status IPv4 addresses
DigiCert certificate status IPv6 addresses
DigiCert moving to new dedicated IPv4 addresses for our DigiCert services and removing support for IPv6 addresses On January 10, 2025, at 08:00 MST (15:00 UTC), DigiCert will move to a new CDN (content delivery network) and assign new dedicated IPv4 addresses to several services to our Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), and a few other DigiCert services. We will also remove support for IPv6 addresses at this time. If your company uses allowlists, update your allowlists to include the new IPv4 addresses by January 10, 2025, to keep your DigiCert services running as they did before the move to the new IPv4 addresses. To learn more, see our change log entry for January 10, 2025, DigiCert moving to new dedicated IPv4 addresses for our DigiCert services and removing support for IPv6 addresses. |
Do you have DigiCert certificates? Do you use allowlists to control inbound and outbound connectivity to your environment?
Then, check the table below and add the necessary IPv4 addresses to your allowlist. You must allow outbound connectivity to these addresses to verify if a certificate should be trusted.
OCSP and CRL distribution endpoints using any of the following subdomains do not use the IPv4 addresses in the table below:
What are OCSPs and CRLs used for?
Your applications and browsers call one of our OCSP or CRL endpoints to learn the revocation status of a DigiCert certificate, such as a TLS or code signing certificate.
Most of the IPv4 addresses are for the DigiCert OCSPs and CRLs. However, we have included some additional PKI Platform 8 services in the table.
Service | URL | IPv4 addresses |
CertCentral Global OCSPs |
|
|
CertCentral Global CRLs |
|
See CertCentral Global OCSPs |
CertCentral Europe OCSPs |
|
|
CertCentral Europe CRLs |
|
See CertCentral Europe OCSPs |
CertCentral Europe CA certificates |
|
See CertCentral Europe OCSPs |
PKI Platform 8 OCSP |
|
|
PKI Platform 8 CRL/CA certificates |
|
See CertCentral Global OCSPs |
PKI client downloads |
|
See CertCentral Global OCSPs |
QuoVadis TrustLink OCSP |
|
|
*DigiCert ONE: If your Trust Lifecycle, Software Trust, or Document Trust Manager (USA, CH, NL, JP) uses public certificates from CertCentral Global, CertCentral Europe, or PKI Platform 8, you may want to add these IPv4 addresses to your allowlist. |
On January 10, 2025, we are moving to a CDN (content delivery network). Unfortunately, we must remove support for IPv6 addresses.