menu menu
  • language
back icon Back
Choose your language
Content Type

 

Knowledge Base

Industry Updates

Google Chrome Root Removal: Trusted Root G4, Assured ID G2, and Assured ID G3

If you use TLS certificates issued from these root hierarchies and require Google Chrome trust, action may be required before July 1, 2026. TLS certificates issued from these root hierarchies before July 1, 2026, remain trusted until they expire. Code Signing certificates issued from these root hierarchies are not affected because they do not rely on browser trust.

Use only current Google-provided Certificate Transparency Enforcement Libraries

Google has announced changes to how Certificate Transparency (CT) log lists are published and maintained.

DigiCert to Enforce CT Logging for All Public TLS Certificates

Starting June 1, 2026, DigiCert will log all public TLS certificates, including canaries and test certificates, to at least one certificate transparency (CT) log.

DigiCert’s Root Strategy: Aligning with New Industry Standards

To enhance digital trust, DigiCert will align our root strategy with the evolving industry standards for issuing public TLS/SSL.

DigiCert IP Address for api.digicert.com

DigiCert Using MPIC to Verify Domain Control and Perform CAA Checks

DigiCert will update MPIC to enforce corroboration using at least three remote network locations from at least two different Regional Internet Registry regions.

Heartbleed Bug Vulnerability

On April 7, 2014, the Heartbleed bug was revealed to the Internet community.

DigiCert transitioning multipurpose G2 and G3 roots to dedicated TLS root hierarchies

To enhance digital trust and comply with the Google Chrome Root Program requirement, DigiCert is transitioning our DigiCert Global Root G2 and DigiCert Global Root G3 roots to single-purpose root hierarchies dedicated to issuing public RSA and ECC TLS end-entity certificates.

API endpoint URL updates for DigiCert’s Certificate Issuing Service (CIS) Platform API

DigiCert will require customers using the CIS Platform API to update API endpoint URLs.

Removing the client authentication EKU from public TLS certificates

Starting October 1, 2025, DigiCert will no longer include the Client Authentication Extended Key Usage (EKU) in our public TLS certificates by default.

New Secure Email (S/MIME) Intermediate CA certificates 2024

On June 26, 2024, at 10:00 MDT (16:00 UTC), DigiCert will move the default issuance of public Secure Email (S/MIME) certificates to new industry-compliant public intermediate CA (ICA) certificates.

DigiCert: Expiring public root and intermediate CA certificates

his knowledge base article lists the public DigiCert Intermediate Certificate Authority (ICA) and Root certificates that expire in the next 42 months (3 ½ years).

Code signing changes in 2023

Starting May 30, 2023, DigiCert requires private keys for code signing certificates to be stored on hardware certified as FIPS 140-2 level 2, Common Criteria EAL 4+, or equivalent that supports 3072-bit or larger keys.

New industry requirements for public Secure Email (S/MIME) certificates

On August 29, 2023, at 10:00 MDT (16:00 UTC), DigiCert will make the changes listed below to our public Secure Email (S/MIME) certificate issuance process to comply with the CA/Brower Forum's new Baseline Requirements for the Issuance and Management of Publicly‐Trusted S/MIME Certificates.

DigiCert timeline: Code signing’s new private key storage requirement

Starting June 1, 2023, at 00:00 UTC, industry standards will require private keys for code signing certificates to be stored on hardware certified as FIPS 140-2 Level 2, Common Criteria EAL 4+, or equivalent.

DigiCert Ireland Limited: New billing entity

DigiCert changed the billing entity for our customers that reside outside the United States or Japan.

Advisory: 8 March 2023 Intermediate Certificate Authorities (ICA) certificates expired

On 8 March 2023, at 05:00 MST (12:00 UTC), the following DigiCert Intermediate Certificate Authority (ICA) certificates expired:

New Dedicated IP Addresses

On February 15, 2023, at 08:00 MST (15:00 UTC), DigiCert assigned new dedicated IP addresses to TLS Online Certificate Status Protocol (OCSP), TLS Certificate Revocation List (CRL), and a few other DigiCert services.

DigiCert Java Spring Framework Response

DigiCert is aware of the zero-day exploit affecting the Java Spring Framework disclosed on March 31, 2022. We continue to analyze this vulnerability and its potential impact on our services.

Apple Distrust

Apple released an update to iOS and macOS systems to fully distrust and remove the Symantec and Verisign roots listed under Affected Certificates.

Federal Common Policy CA Update

The US government revoked DigiCert Federal SSP Intermediate CA - G5, the intermediate cert bridging trust between Digicert and the Federal Common

Code signing changes in 2021

Starting from May 28, 2021, 14:00 MDT (20:00 UTC), DigiCert will require 3072-bit RSA keys or larger for code signing certificates.

Domain validation policy changes in 2021

Reduced validity of domain validation and removal of file authentication domain control validation (DCV) for wildcard certificates.

HTTP Practical Demonstration and allowlisting DigiCert IP addresses

Depending on your firewall configurations, you may need to "allow-list" DigiCert IP addresses for the HTTP token domain approval process to go through.

Symantec Root Removal

Symantec code signing certificates issued after February 23, 2021, will not be publicly trusted in the Microsoft root store.

DigiCert Stopped Issuing SHA-1 Code Signing Certificates

DigiCert stopped issuing SHA-1 code signing and SHA-1 EV code signing certificates on December 1, 2020. All existing SHA-1 code signing/EV code signing certificates will remain active until they expire.

DigiCert will deprecate the Organizational Unit field

OU field will no longer appear in order forms, will be ignored in API requests, and will be removed in all new, renewed, and reissued public TLS certificates.

DigiCert ICA Update

Always include the provided ICA with every certificate you install to ensure replacements go unnoticed & to make sure certificates are trusted.

IP Address Changes

As of September 13, 2020, DigiCert assigned new dedicated IP addresses to our CertCentral mail server, some of our services, and APIs.

Identify Certificates Impacted by Potential Chrome Distrust

Browsers and root program owners have plans to remove trust of all legacy Symantec SSL/TLS certificates issued under the Symantec infrastructure.

DigiCert ICA Replacement

DigiCert has identified an issue where some of our intermediate CAs (ICAs) were not listed as part of our most recent WebTrust EV audit.

Microsoft sunsetting support for Cross-Signed Root Certificates with Kernel-Mode Signing capabilities

Microsoft announced the Microsoft Trusted Root Program is ending support for cross-signed root certificates with kernel-mode signing capabilities.

Enforcement of DigiCert​​®​​ KeyLocker service limits

On November 3, 2023, DigiCert introduced new limits for customers with code signing certificates stored in KeyLocker.

End of life for WHOIS-based DCV methods

To comply with industry changes mandated by the ballot, certificate authorities must stop using WHOIS to identify domain contacts for email, fax, SMS, postal mail, and phone domain control validation methods.

DigiCert IP Addresses Flagged by Malware Report

During the standard certificate verification process, systems utilize OCSP and CRL checks to determine if a certificate is valid.

New Certificate Profile Requirements for Public Secure Email (S/MIME) Certificates 2025

The S/MIME Baseline Requirements currently support three certificate profiles for Secure Email (S/MIME) certificates: Strict, Multipurpose, and Legacy.

SSL Certificates for Internal Server Names

An internal name is a domain or IP address that's part of a private network.

Install the DigiCert G5 cross-signed root CA certificate

To prepare for this change, DigiCert has created new, single-purpose, public, fifth-generation (G5) root and intermediate CA (ICA) certificate hierarchies for issuing public TLS/SSL certificates.

Transitioning public S/MIME certificate issuance from PKI Platform 8 to Trust Lifecycle Manager in DigiCert ONE

End of issuance of public S/MIME (Secure Email) certificates from DigiCert® PKI Platform 8 is scheduled for March 14, 2025

Cloud-based private key storage with DigiCert® KeyLocker

DigiCert KeyLocker is an automated alternative to manually generating and storing your private key on a hardware token that can be lost or stolen or purchasing a hardware security module (HSM) and storing it on-premises.

Signing Kernel Mode Drivers

The process for kernel mode drivers has changed as of April 2021.

DigiCert Driver Signing Certificates for Microsoft Windows

Starting in 2021, Microsoft will be the sole provider of production kernel-mode code signatures. You will need to start following Microsoft’s updated instructions to sign any new kernel-mode driver packages going forward.

Ending Support for CBC Ciphers in TLS connections to our services

On October 8, 2022, at 22:00 MDT (October 9, 2022, at 04:00 UTC), DigiCert will end support for Cipher-Block-Chaining (CBC) ciphers in TLS connections to our services to align with Payment card industry (PCI) standards.

DigiCert G5 root and intermediate CA certificate update

DigiCert has postponed updating our default public issuance of TLS/SSL certificate to new, public, fifth-generation (G5) root and intermediate CA (ICA) certificate hierarchy.

Compatibility of DigiCert Trusted Root Certificates

DigiCert’s Trusted Root Certificates (DigiCert Global Root CA and DigiCert Global Root G2) are compatible with all modern browsers and platforms.

New private key storage requirement for Code Signing certificates

Starting on June 1, 2023, at 00:00 UTC, industry standards will require private keys for standard code signing certificates to be stored on hardware certified as FIPS 140 Level 2, Common Criteria EAL 4+, or equivalent.

DigiCert CertCentral Services API beta server

On May 31, 2022, DigiCert will improve the data we return when you submit a request to the Order info API endpoint.

RFC3161 compliant Time Stamp Authority (TSA) server

An RFC3161 timestamp server provides an essential function in protecting data records for the long-term.