Change of Default Root CA from October 2026
(October 2, 2026) Starting October 15, 2026, DigiCert will begin issuing all public TLS certificates from new G5 root certificates. If you install the complete certificate chain, you usually don't need to do anything. However, check trust stores, pinning, and automated integrations. From September 2027, Chrome will no longer trust certificates from older G2 and G3 roots.
DigiCert Issuing TLS Certificates from New G5 Roots from October 15, 2026
From October 15, 2026, DigiCert will by default issue all publicly trusted TLS certificates from the new G5 root hierarchies:
- DigiCert TLS RSA4096 Root G5
- DigiCert TLS ECC P384 Root G5
The change affects new orders, renewals, reissues, and duplicates for all types of certificates (DV, OV, EV) under the DigiCert, GeoTrust, Thawte, RapidSSL, and Encryption Everywhere brands. Already issued certificates remain valid until their expiration.
Why the Change
Google Chrome limits the number of active TLS roots from a single certificate authority to two. From September 15, 2027, Chrome will only trust DigiCert's G5 roots. Certificates from the existing Global G2 and G3 roots will no longer be trusted by Chrome from this date.
Does This Affect Me?
Yes, the change affects all users of DigiCert public TLS certificates. If you always install the complete certificate chain provided by DigiCert (server certificate, intermediate CA, and possibly cross-signed root), you usually don't have to do anything.
Action is required in the following cases:
- You install only the server certificate without the chain: Always install the entire chain.
- You manage your own trust store: Add the G5 root and intermediate certificates.
- You have hardcoded trust in a specific root or intermediate certificate: Remove it.
- You use pinning for root or intermediate certificates: Remove pinning. Certificate authorities will change intermediate certificates regularly, approximately once a year from October 2027.
- Older clients without G5 root: Add cross-signed root to the server chain (G2 for RSA, G3 for ECC).
- Automation (API, ACME): Verify that the integration does not have a specific intermediate CA set. Without explicit setting, it will automatically transition to G5.
We recommend using the time until October 15 to verify your servers, devices, and integrations. We are happy to help you with the check or transition.