Dear Tencent Cloud SSL Certificate User,
To comply with browser root certificate programs and CA/Browser Forum industry requirements, and to enhance the security and cryptographic agility of the publicly trusted TLS certificate ecosystem, GlobalSign has activated its new TLS-dedicated root certificates R46/E46, and DigiCert plans to migrate its publicly trusted TLS certificates to the dedicated G5 root certificate hierarchy. In addition, TrustAsia plans to change the intermediate root certificate used by its free certificates. This announcement explains the timeline, certificate chain changes, scope of impact, and our recommendations for these adjustments. Please make the necessary preparations in advance.
I. Root Certificate Upgrade for DigiCert and GlobalSign SSL Certificates
1. Adjustment Schedule
Brand | Effective Date | Change |
GlobalSign | July 27, 2026 (already in effect) | New TLS-dedicated root certificates R46/E46 activated |
DigiCert and its sub-brands | October 15, 2026 | TLS-dedicated root certificate G5 activated |
2. Details of Root Certificate and Certificate Chain Changes
2.1 GlobalSign Certificate Chain Changes
On July 27, 2026, GlobalSign migrated the publicly trusted TLS certificates of its customers and partners to the TLS-dedicated root certificate hierarchy, in which RSA certificates use GlobalSign Root R46 and ECC certificates use GlobalSign Root E46. After the migration, publicly trusted TLS certificates retain only the Server Authentication (ServerAuth) extended key usage and no longer include the Client Authentication (ClientAuth) extended key usage.
Top-level root certificate changes:
Algorithm | Previous Root Certificate | New Root Certificate |
RSA | GlobalSign Root R3/R6 | GlobalSign Root R46 |
ECC | GlobalSign Root R5 | GlobalSign Root E46 |
Comparison of certificate chain changes (using an RSA DV SSL certificate as an example):
Item | Before the Change | After the Change |
Root certificate | GlobalSign Root R3 | GlobalSign Root R46 |
Cross-signing root certificate | GlobalSign Root CA | GlobalSign Root R3 |
Root certificate validity | March 18, 2009 – March 18, 2029 | March 20, 2019 – March 20, 2046 |
Cross-signing root certificate validity | September 1, 1998 – January 28, 2028 | March 18, 2009 – March 18, 2029 |
Apple | MacOS 9.0+ / MacOS X 10.5.6+ / iOS 3+ / Safari 1+ | MacOS X 10.6.4+ / iOS 4+ / Safari 4+ |
Mozilla | Firefox 1.0+ / NSS 3.11.10+ | Firefox 3.6.12+ / NSS 3.12.8+ |
Microsoft | XP / Vista / Windows 7+ / IE 5.01 / Microsoft Edge | XP / Vista / Windows 7+ / IE 8+ / Microsoft Edge |
Android | Android 1+ | Android 3+ |
Chrome | Not supported | Supported |
Java | SE 5+ | SE 8+ |
Opera | 6.1+ | 10+ |
Blackberry | 4.3+ | 5+ |
Sony | PS Portable / PS 3 / PS 4 | PS Portable / PS 3 / PS 4 |
Nintendo | Wii / Wii U / DS | Wii / Wii U / DS |
2.2 DigiCert Certificate Chain Changes
Starting October 15, 2026, DigiCert will use DigiCert TLS RSA 4096 Root G5 (RSA) or DigiCert TLS ECC P384 Root G5 (ECC) by default to issue publicly trusted TLS certificates. This change applies to publicly trusted DV, OV, and EV TLS certificates across all DigiCert brands.
Top-level root certificate changes:
Algorithm | Previous Root Certificate | New Root Certificate |
RSA | DigiCert Global Root G2 | DigiCert TLS RSA 4096 Root G5 |
ECC | DigiCert Global Root G3 | DigiCert TLS ECC P384 Root G5 |
Comparison of certificate chain changes (using an RSA DV SSL certificate as an example):
Item | Before the Change | After the Change |
Root certificate | DigiCert Global Root G2 | DigiCert TLS RSA 4096 Root G5 |
Cross-signing root certificate | DigiCert Global Root CA | DigiCert Global Root G2 |
Root certificate validity | August 1, 2013 – January 15, 2038 | January 15, 2021 – January 14, 2046 |
Cross-signing root certificate validity | November 10, 2006 – November 10, 2031 | August 1, 2013 – January 15, 2038 |
Apple | Mac OS X 10.6+ / iOS 4.0+ | Mac OS X 10.10+ / iOS 7.0+ |
Mozilla | Firefox 2+ / NSS 3.11.8+ | Firefox 32+ / NSS 3.16.3 |
Microsoft | Windows XP SP3+ | Windows XP SP3+ |
Google | Android 1.1+ | Android 5.0+ |
Oracle | JRE 1.4.2_17+ | JRE 1.8.0_131+ |
3. Scope of Impact
3.1 GlobalSign and Its Sub-brands
Since July 27, 2026, all of your GlobalSign certificates (including new orders, renewals, and reissues) have been automatically upgraded to the R46/E46 dedicated root certificate hierarchy when the publicly trusted TLS certificates are issued.
This upgrade does not affect certificates that have already been issued; they remain usable until their own expiration dates.
3.2 DigiCert and Its Sub-brands
Starting October 15, 2026, all of your DigiCert and sub-brand certificates (including new orders, renewals, and reissues) will be automatically upgraded to the G5 dedicated root certificate hierarchy upon issuance.
This upgrade does not affect certificates that have already been issued; they remain usable until their own expiration dates.
4. Compatibility Notes
4.1 GlobalSign R46/E46
To maintain compatibility with the legacy R3 and R5 roots, GlobalSign has made cross-signed certificates available for download. The cross-signing relationships of the root certificates are as follows:
Algorithm | Root Certificate | Cross-signed Root Certificate |
RSA | GlobalSign Root R46 | GlobalSign Root R3 |
ECC | GlobalSign Root E46 | GlobalSign ECC Root R5 |
4.2 DigiCert G5
The DigiCert G5 TLS root certificates are trusted by Google Chrome and other mainstream browsers. DigiCert also provides cross-signed chains issued by DigiCert Global Root G2/G3 to improve compatibility. The cross-signing relationships are as follows:
Algorithm | G5 Root Certificate | Cross-signed Root Certificate |
RSA | DigiCert TLS RSA 4096 Root G5 | DigiCert Global Root G2 |
ECC | DigiCert TLS ECC P384 Root G5 | DigiCert Global Root G3 |
5. Recommendations
PC and server-side users: Verify that the new root certificates are pre-installed on your devices, or manually update the certificate chain after the certificate is upgraded.
Mobile app users: If root certificates are embedded in your app, update the certificate configuration in the app before the upgrade.
IoT device users: Confirm in advance whether your device firmware supports the new root certificates, and upgrade the firmware if necessary.
II. Intermediate Root Certificate Switch for Tencent Cloud TrustAsia Free Certificates
1. Adjustment Schedule
TrustAsia plans to change the intermediate root certificate used by TrustAsia free certificates on October 15, 2026.
After the switch, newly requested certificates will be issued under the new certificate chain. Free certificates issued before the switch and still within their validity period are not affected and remain usable until their own expiration dates.
2. Details of the Change
This switch involves the following two changes:
2.1 Intermediate Root Certificate Switch
Algorithm | Previous Certificate Chain | New Certificate Chain |
RSA | TrustAsia DV TLS RSA CA 2024 -> TrustAsia TLS RSA Root CA -> Certum Trusted Network CA | LiteSSL RSA CA 2025 -> TrustAsia TLS RSA Root CA -> Certum Trusted Network CA |
ECC | TrustAsia DV TLS ECC CA 2024 -> TrustAsia TLS ECC Root CA -> Certum Trusted Network CA | LiteSSL ECC CA 2025 -> TrustAsia TLS ECC Root CA -> Certum Trusted Network CA |
2.2 Change in RSA Certificate Key Usage
Before the Switch | After the Switch |
RSA certificates support Digital Signature and Key Encipherment | RSA certificates support Digital Signature only, and no longer support Key Encipherment |
Note:
After the switch, RSA certificates retain only the Digital Signature key usage and no longer include Key Encipherment. This change is intended to drive the WebPKI ecosystem toward TLS 1.3 and ECDHE key exchange, which provide forward secrecy. Servers should give priority to enabling ECDHE cipher suites, and we strongly recommend disabling the legacy TLS_RSA_ key exchange, which is less secure and does not provide forward secrecy. If your server is configured only with the insecure TLS_RSA_ key exchange, SSL/TLS handshakes may fail. Before requesting a new certificate, please complete compatibility testing and confirm that your server has correctly enabled modern TLS protocols and ECDHE cipher suites.
Thank you for your continued trust in and support of Tencent Cloud SSL Certificate Service. We remain committed to providing you with secure and reliable digital certificate services.