tencent cloud

このページは現在英語のみで、表示されている言語を準備しています。
关闭
[SSL Certificates] Notice Regarding Root Certificate Upgrades for DigiCert, GlobalSign, CFCA, and TrustAsia Free Certificates
2026-09-03 10:08:35
Dear Tencent Cloud SSL Certificate User,
To comply with browser root certificate programs and CA/Browser Forum industry requirements, and to enhance the security and cryptographic agility of the publicly trusted TLS certificate ecosystem, GlobalSign has activated its new TLS-dedicated root certificates R46/E46, and DigiCert plans to migrate its publicly trusted TLS certificates to the dedicated G5 root certificate hierarchy. In addition, TrustAsia plans to change the intermediate root certificate used by its free certificates. This announcement explains the timeline, certificate chain changes, scope of impact, and our recommendations for these adjustments. Please make the necessary preparations in advance.


I. Root Certificate Upgrade for DigiCert and GlobalSign SSL Certificates

1. Adjustment Schedule
Brand
Effective Date
Change
GlobalSign
July 27, 2026 (already in effect)
New TLS-dedicated root certificates R46/E46 activated
DigiCert and its sub-brands
October 15, 2026
TLS-dedicated root certificate G5 activated
2. Details of Root Certificate and Certificate Chain Changes
2.1 GlobalSign Certificate Chain Changes
On July 27, 2026, GlobalSign migrated the publicly trusted TLS certificates of its customers and partners to the TLS-dedicated root certificate hierarchy, in which RSA certificates use GlobalSign Root R46 and ECC certificates use GlobalSign Root E46. After the migration, publicly trusted TLS certificates retain only the Server Authentication (ServerAuth) extended key usage and no longer include the Client Authentication (ClientAuth) extended key usage.
Top-level root certificate changes:
Algorithm
Previous Root Certificate
New Root Certificate
RSA
GlobalSign Root R3/R6
GlobalSign Root R46
ECC
GlobalSign Root R5
GlobalSign Root E46
Comparison of certificate chain changes (using an RSA DV SSL certificate as an example):
Item
Before the Change
After the Change
Root certificate
GlobalSign Root R3
GlobalSign Root R46
Cross-signing root certificate
GlobalSign Root CA
GlobalSign Root R3
Root certificate validity
March 18, 2009 – March 18, 2029
March 20, 2019 – March 20, 2046
Cross-signing root certificate validity
September 1, 1998 – January 28, 2028
March 18, 2009 – March 18, 2029
Apple
MacOS 9.0+ / MacOS X 10.5.6+ / iOS 3+ / Safari 1+
MacOS X 10.6.4+ / iOS 4+ / Safari 4+
Mozilla
Firefox 1.0+ / NSS 3.11.10+
Firefox 3.6.12+ / NSS 3.12.8+
Microsoft
XP / Vista / Windows 7+ / IE 5.01 / Microsoft Edge
XP / Vista / Windows 7+ / IE 8+ / Microsoft Edge
Android
Android 1+
Android 3+
Chrome
Not supported
Supported
Java
SE 5+
SE 8+
Opera
6.1+
10+
Blackberry
4.3+
5+
Sony
PS Portable / PS 3 / PS 4
PS Portable / PS 3 / PS 4
Nintendo
Wii / Wii U / DS
Wii / Wii U / DS
2.2 DigiCert Certificate Chain Changes
Starting October 15, 2026, DigiCert will use DigiCert TLS RSA 4096 Root G5 (RSA) or DigiCert TLS ECC P384 Root G5 (ECC) by default to issue publicly trusted TLS certificates. This change applies to publicly trusted DV, OV, and EV TLS certificates across all DigiCert brands.
Top-level root certificate changes:
Algorithm
Previous Root Certificate
New Root Certificate
RSA
DigiCert Global Root G2
DigiCert TLS RSA 4096 Root G5
ECC
DigiCert Global Root G3
DigiCert TLS ECC P384 Root G5
Comparison of certificate chain changes (using an RSA DV SSL certificate as an example):
Item
Before the Change
After the Change
Root certificate
DigiCert Global Root G2
DigiCert TLS RSA 4096 Root G5
Cross-signing root certificate
DigiCert Global Root CA
DigiCert Global Root G2
Root certificate validity
August 1, 2013 – January 15, 2038
January 15, 2021 – January 14, 2046
Cross-signing root certificate validity
November 10, 2006 – November 10, 2031
August 1, 2013 – January 15, 2038
Apple
Mac OS X 10.6+ / iOS 4.0+
Mac OS X 10.10+ / iOS 7.0+
Mozilla
Firefox 2+ / NSS 3.11.8+
Firefox 32+ / NSS 3.16.3
Microsoft
Windows XP SP3+
Windows XP SP3+
Google
Android 1.1+
Android 5.0+
Oracle
JRE 1.4.2_17+
JRE 1.8.0_131+
3. Scope of Impact
3.1 GlobalSign and Its Sub-brands
Since July 27, 2026, all of your GlobalSign certificates (including new orders, renewals, and reissues) have been automatically upgraded to the R46/E46 dedicated root certificate hierarchy when the publicly trusted TLS certificates are issued.
This upgrade does not affect certificates that have already been issued; they remain usable until their own expiration dates.
3.2 DigiCert and Its Sub-brands
Starting October 15, 2026, all of your DigiCert and sub-brand certificates (including new orders, renewals, and reissues) will be automatically upgraded to the G5 dedicated root certificate hierarchy upon issuance.
This upgrade does not affect certificates that have already been issued; they remain usable until their own expiration dates.
4. Compatibility Notes
4.1 GlobalSign R46/E46
To maintain compatibility with the legacy R3 and R5 roots, GlobalSign has made cross-signed certificates available for download. The cross-signing relationships of the root certificates are as follows:
Algorithm
Root Certificate
Cross-signed Root Certificate
RSA
GlobalSign Root R46
GlobalSign Root R3
ECC
GlobalSign Root E46
GlobalSign ECC Root R5
4.2 DigiCert G5
The DigiCert G5 TLS root certificates are trusted by Google Chrome and other mainstream browsers. DigiCert also provides cross-signed chains issued by DigiCert Global Root G2/G3 to improve compatibility. The cross-signing relationships are as follows:
Algorithm
G5 Root Certificate
Cross-signed Root Certificate
RSA
DigiCert TLS RSA 4096 Root G5
DigiCert Global Root G2
ECC
DigiCert TLS ECC P384 Root G5
DigiCert Global Root G3
5. Recommendations
PC and server-side users: Verify that the new root certificates are pre-installed on your devices, or manually update the certificate chain after the certificate is upgraded.
Mobile app users: If root certificates are embedded in your app, update the certificate configuration in the app before the upgrade.
IoT device users: Confirm in advance whether your device firmware supports the new root certificates, and upgrade the firmware if necessary.

II. Intermediate Root Certificate Switch for Tencent Cloud TrustAsia Free Certificates

1. Adjustment Schedule
TrustAsia plans to change the intermediate root certificate used by TrustAsia free certificates on October 15, 2026.
After the switch, newly requested certificates will be issued under the new certificate chain. Free certificates issued before the switch and still within their validity period are not affected and remain usable until their own expiration dates.
2. Details of the Change
This switch involves the following two changes:
2.1 Intermediate Root Certificate Switch
Algorithm
Previous Certificate Chain
New Certificate Chain
RSA
TrustAsia DV TLS RSA CA 2024 -> TrustAsia TLS RSA Root CA -> Certum Trusted Network CA
LiteSSL RSA CA 2025 -> TrustAsia TLS RSA Root CA -> Certum Trusted Network CA
ECC
TrustAsia DV TLS ECC CA 2024 -> TrustAsia TLS ECC Root CA -> Certum Trusted Network CA
LiteSSL ECC CA 2025 -> TrustAsia TLS ECC Root CA -> Certum Trusted Network CA
2.2 Change in RSA Certificate Key Usage
Before the Switch
After the Switch
RSA certificates support Digital Signature and Key Encipherment
RSA certificates support Digital Signature only, and no longer support Key Encipherment
Note:
After the switch, RSA certificates retain only the Digital Signature key usage and no longer include Key Encipherment. This change is intended to drive the WebPKI ecosystem toward TLS 1.3 and ECDHE key exchange, which provide forward secrecy. Servers should give priority to enabling ECDHE cipher suites, and we strongly recommend disabling the legacy TLS_RSA_ key exchange, which is less secure and does not provide forward secrecy. If your server is configured only with the insecure TLS_RSA_ key exchange, SSL/TLS handshakes may fail. Before requesting a new certificate, please complete compatibility testing and confirm that your server has correctly enabled modern TLS protocols and ECDHE cipher suites.

Thank you for your continued trust in and support of Tencent Cloud SSL Certificate Service. We remain committed to providing you with secure and reliable digital certificate services.


img