If you use TLS certificates issued from these root hierarchies and require Google Chrome trust, action may be required before July 1, 2026. TLS certificates issued from these root hierarchies before July 1, 2026, remain trusted until they expire. Code Signing certificates issued from these root hierarchies are not affected because they do not rely on browser trust.
Google has announced changes to how Certificate Transparency (CT) log lists are published and maintained.
Starting June 1, 2026, DigiCert will log all public TLS certificates, including canaries and test certificates, to at least one certificate transparency (CT) log.
To enhance digital trust, DigiCert will align our root strategy with the evolving industry standards for issuing public TLS/SSL.
DigiCert will update MPIC to enforce corroboration using at least three remote network locations from at least two different Regional Internet Registry regions.
On April 7, 2014, the Heartbleed bug was revealed to the Internet community.
To enhance digital trust and comply with the Google Chrome Root Program requirement, DigiCert is transitioning our DigiCert Global Root G2 and DigiCert Global Root G3 roots to single-purpose root hierarchies dedicated to issuing public RSA and ECC TLS end-entity certificates.
DigiCert will require customers using the CIS Platform API to update API endpoint URLs.
Starting October 1, 2025, DigiCert will no longer include the Client Authentication Extended Key Usage (EKU) in our public TLS certificates by default.
On June 26, 2024, at 10:00 MDT (16:00 UTC), DigiCert will move the default issuance of public Secure Email (S/MIME) certificates to new industry-compliant public intermediate CA (ICA) certificates.
his knowledge base article lists the public DigiCert Intermediate Certificate Authority (ICA) and Root certificates that expire in the next 42 months (3 ½ years).
Starting May 30, 2023, DigiCert requires private keys for code signing certificates to be stored on hardware certified as FIPS 140-2 level 2, Common Criteria EAL 4+, or equivalent that supports 3072-bit or larger keys.
On August 29, 2023, at 10:00 MDT (16:00 UTC), DigiCert will make the changes listed below to our public Secure Email (S/MIME) certificate issuance process to comply with the CA/Brower Forum's new Baseline Requirements for the Issuance and Management of Publicly‐Trusted S/MIME Certificates.
Starting June 1, 2023, at 00:00 UTC, industry standards will require private keys for code signing certificates to be stored on hardware certified as FIPS 140-2 Level 2, Common Criteria EAL 4+, or equivalent.
DigiCert changed the billing entity for our customers that reside outside the United States or Japan.
On 8 March 2023, at 05:00 MST (12:00 UTC), the following DigiCert Intermediate Certificate Authority (ICA) certificates expired:
On February 15, 2023, at 08:00 MST (15:00 UTC), DigiCert assigned new dedicated IP addresses to TLS Online Certificate Status Protocol (OCSP), TLS Certificate Revocation List (CRL), and a few other DigiCert services.
DigiCert is aware of the zero-day exploit affecting the Java Spring Framework disclosed on March 31, 2022. We continue to analyze this vulnerability and its potential impact on our services.
Apple released an update to iOS and macOS systems to fully distrust and remove the Symantec and Verisign roots listed under Affected Certificates.
The US government revoked DigiCert Federal SSP Intermediate CA - G5, the intermediate cert bridging trust between Digicert and the Federal Common
Starting from May 28, 2021, 14:00 MDT (20:00 UTC), DigiCert will require 3072-bit RSA keys or larger for code signing certificates.
Reduced validity of domain validation and removal of file authentication domain control validation (DCV) for wildcard certificates.
Depending on your firewall configurations, you may need to "allow-list" DigiCert IP addresses for the HTTP token domain approval process to go through.
Symantec code signing certificates issued after February 23, 2021, will not be publicly trusted in the Microsoft root store.
DigiCert stopped issuing SHA-1 code signing and SHA-1 EV code signing certificates on December 1, 2020. All existing SHA-1 code signing/EV code signing certificates will remain active until they expire.
OU field will no longer appear in order forms, will be ignored in API requests, and will be removed in all new, renewed, and reissued public TLS certificates.
Always include the provided ICA with every certificate you install to ensure replacements go unnoticed & to make sure certificates are trusted.
As of September 13, 2020, DigiCert assigned new dedicated IP addresses to our CertCentral mail server, some of our services, and APIs.
Browsers and root program owners have plans to remove trust of all legacy Symantec SSL/TLS certificates issued under the Symantec infrastructure.
DigiCert has identified an issue where some of our intermediate CAs (ICAs) were not listed as part of our most recent WebTrust EV audit.
Microsoft announced the Microsoft Trusted Root Program is ending support for cross-signed root certificates with kernel-mode signing capabilities.
On November 3, 2023, DigiCert introduced new limits for customers with code signing certificates stored in KeyLocker.
To comply with industry changes mandated by the ballot, certificate authorities must stop using WHOIS to identify domain contacts for email, fax, SMS, postal mail, and phone domain control validation methods.
During the standard certificate verification process, systems utilize OCSP and CRL checks to determine if a certificate is valid.
The S/MIME Baseline Requirements currently support three certificate profiles for Secure Email (S/MIME) certificates: Strict, Multipurpose, and Legacy.
An internal name is a domain or IP address that's part of a private network.
To prepare for this change, DigiCert has created new, single-purpose, public, fifth-generation (G5) root and intermediate CA (ICA) certificate hierarchies for issuing public TLS/SSL certificates.
End of issuance of public S/MIME (Secure Email) certificates from DigiCert® PKI Platform 8 is scheduled for March 14, 2025
DigiCert KeyLocker is an automated alternative to manually generating and storing your private key on a hardware token that can be lost or stolen or purchasing a hardware security module (HSM) and storing it on-premises.
The process for kernel mode drivers has changed as of April 2021.
Starting in 2021, Microsoft will be the sole provider of production kernel-mode code signatures. You will need to start following Microsoft’s updated instructions to sign any new kernel-mode driver packages going forward.
On October 8, 2022, at 22:00 MDT (October 9, 2022, at 04:00 UTC), DigiCert will end support for Cipher-Block-Chaining (CBC) ciphers in TLS connections to our services to align with Payment card industry (PCI) standards.
DigiCert has postponed updating our default public issuance of TLS/SSL certificate to new, public, fifth-generation (G5) root and intermediate CA (ICA) certificate hierarchy.
DigiCert’s Trusted Root Certificates (DigiCert Global Root CA and DigiCert Global Root G2) are compatible with all modern browsers and platforms.
Starting on June 1, 2023, at 00:00 UTC, industry standards will require private keys for standard code signing certificates to be stored on hardware certified as FIPS 140 Level 2, Common Criteria EAL 4+, or equivalent.
On May 31, 2022, DigiCert will improve the data we return when you submit a request to the Order info API endpoint.
An RFC3161 timestamp server provides an essential function in protecting data records for the long-term.