Change of Default Root CA from October 2026
(October 2, 2026) From October 15, 2026, DigiCert will start issuing all public TLS certificates from new G5 root certificates. If you install the complete certificate chain, you usually don't need to do anything. However, check the trust store, pinning, and automated integrations. From September 2027, Chrome will stop trusting certificates from the older G2 and G3 roots.
DigiCert Issues TLS Certificates from New G5 Roots Starting October 15, 2026
From October 15, 2026, DigiCert will by default issue all publicly trusted TLS certificates from the new G5 root hierarchies:
- DigiCert TLS RSA4096 Root G5
- DigiCert TLS ECC P384 Root G5
The change applies to new orders, renewals, reissues, and duplicates, for all types of certificates (DV, OV, EV) under the DigiCert, GeoTrust, Thawte, RapidSSL, and Encryption Everywhere brands. Already issued certificates remain valid until the end of their validity.
Why the Change Is Happening
Google Chrome limits the number of active TLS roots from one certificate authority to two. From September 15, 2027, Chrome will only trust the G5 roots of DigiCert. Chrome will stop trusting certificates from the current Global G2 and G3 roots from this date.
Does This Affect Me?
Yes, the change affects all users of public TLS certificates issued by DigiCert. If you always install the complete certificate chain provided by DigiCert (server certificate, intermediate CA, and possibly cross-signed root), you usually don't need to do anything.
Action is required in these cases:
- You install only the server certificate without a chain: Always install the entire chain.
- You manage your own trust store: Add the G5 root and intermediate certificates.
- You have hardcoded trust in a specific root or intermediate certificate: Remove it.
- You use pinning for root or intermediate certificates: Remove the pinning. Certificate authorities will regularly change intermediate certificates, approximately once a year from October 2027.
- Older clients without the G5 root: Add a cross-signed root to the server chain (G2 for RSA, G3 for ECC).
- Automation (API, ACME): Check if the integration has a specific intermediate CA hard set. Without explicit setting, it will automatically switch to G5.
We recommend using the time until October 15 to verify your servers, devices, and integrations. We are happy to help you with the check or transition.