Skip to main content

[Notice] Notice on the Migration of DigiCert TLS Certificates to the G5 Root

Dear Customer,

 Hello! Thank you for your long-standing trust and support in Racent!

 According to the official notice from DigiCert, starting October 15, 2026, DigiCert will make important adjustments to the issuing root certificates for browser-trusted TLS certificates (applicable to browsers such as Chrome, Safari, Firefox, etc.). At that time, DV, OV, and EV TLS certificates issued through DigiCert will be chained to one of the following two G5 root certificates by default:

  • DigiCert TLS RSA4096 Root G5
  • DigiCert TLS ECC P384 Root G5

 To ensure a smooth transition for your business, we hereby inform you of the relevant matters as follows:

I. Impact on You and Matters Requiring Attention

  • Most users do not need to take any action: Newly issued certificates starting from October 15, 2026 will automatically include the new G5 root certificate hierarchy, which will be processed by the system by default.
  • Previously issued certificates will not be affected: All certificates issued before October 15, 2026 can be used normally until their expiration.
  • Regarding certificate pinning: If you currently use certificate pinning or hard-coded certificates in your environment, we recommend that you review the existing environment before October 15, 2026, and begin to phase out this practice. As certificate rotation frequency continues to increase, continuing to use pinning methods may increase the risk of unexpected outages.
  • Non-browser application scenarios: If your application or device relies on publicly trusted TLS certificates but is not used in a browser environment, we recommend that you evaluate migrating to a trust model more suitable for non-browser scenarios (such as private certificates, X9 certificates, or DigiCert non-browser public trust hierarchy certificates). If needed, you can contact our company for support at any time.
  • Special note: QWAC (Qualified Website Authentication Certificate) and QWAC PSD2 certificates are not directly affected by this change, and details of the relevant certificate chains will be notified separately.

II. Reasons for the Change

 This adjustment is to comply with Google Chrome's requirements for simplifying the root certificate store (limiting each Certificate Authority (CA) to embedding only two active TLS root certificates). Accordingly, DigiCert will unify the issuance of browser-trusted TLS certificates under the G5 TLS root certificates, while continuing to provide services for non-browser use cases through the Assured ID G2 root certificate.

III. Notice of Important Changes in 2027

 This G5 hierarchy transition is the first step in DigiCert's long-term plan. Starting October 15, 2027, DigiCert will also launch an annual rotation plan for browser-trusted TLS Intermediate Certificate Authorities (ICAs), gradually transitioning to shorter-validity ICAs and root certificates. We recommend that you pay attention in advance and make proper plans.

 Racent (www.racent.com) is committed to automated SSL certificate operation and maintenance, providing automated solutions such as sslTrus CLM and CaaS. At the same time, as a professional digital certificate vendor and compliance agent for world-renowned CAs, we provide trusted digital certificate products.