{"id":4622,"date":"2026-04-16T10:12:19","date_gmt":"2026-04-16T10:12:19","guid":{"rendered":"https:\/\/certera.com\/blog\/?p=4622"},"modified":"2026-04-16T10:12:20","modified_gmt":"2026-04-16T10:12:20","slug":"digicert-g1-root-removal-2026-what-it-means-what-actions-to-do","status":"publish","type":"post","link":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/","title":{"rendered":"DigiCert G1 Root Removal 2026: What It Means, Risks &amp; Action Plan for Your TLS Infrastructure"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-digicert-g1-retirement-2026-a-turning-point-in-web-pki-evolution\">DigiCert G1 Retirement 2026: A Turning Point in Web PKI Evolution<\/h2>\n\n\n\n<p class=\"quote-section wp-block-paragraph\">Mozilla and Google Chrome will <a href=\"https:\/\/knowledge.digicert.com\/alerts\/digicert-tls-root-strategy-aligning-with-industry-standards\">revoke the G1 root certificates of DigiCert<\/a> on April 15, 2026. When the certificate you are using TLS chains to one of those roots, the browsers immediately do not trust it. A security warning is shown to your users. Breaking your login flows. Your payment page is a wall.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is not a browser bug. Your infrastructure on the nose.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-can-it-disrupt-your-secure-connections\">How Can It Disrupt Your Secure Connections?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is what is particularly dangerous: even with a certificate that is not expired, not revoked, not with any problems on paper, a warning about untrusted prompts as soon as this change comes into effect. Having an expiry date on your cert is irrelevant when the root that it chains to is no longer trusted.<\/p>\n\n\n\n<p class=\"quote-section wp-block-paragraph\">The majority of DigiCert customers were transferred to G2 hierarchies back in March 2023 and do not have to do anything. However, to the organisations that continue to use older chains, particularly within a legacy environment, custom trust stores, or non-standard deployments, this is a very real, business-affecting risk.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-important-dates-changes-and-actions\">Important Dates, Changes, and Actions<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Deadline<\/strong><\/td><td><strong>What changes<\/strong><\/td><td><strong>Who&#8217;s affected<\/strong><\/td><td><strong>Action<\/strong><\/td><td><strong>Urgency<\/strong><\/td><\/tr><tr><td><strong>Apr 15, 2026<\/strong><\/td><td>DigiCert G1 roots removed from Chrome &amp; Mozilla trust stores &nbsp;<\/td><td>Anyone with active TLS certs still chaining to G1 roots &nbsp;<\/td><td>Reissue into G2 or G3 before this date &nbsp;<\/td><td>Critical &nbsp;<\/td><\/tr><tr><td><strong>May 15, 2026<\/strong><\/td><td><br>G2\/G3 intermediate CA certs and two G5 cross-signed roots revoked &nbsp;<\/td><td>Orgs with S\/MIME, Code Signing, or cross-signed chain dependencies &nbsp;<\/td><td>Switch to new ICA certs, replace cross-signed roots in chain &nbsp;<\/td><td>High &nbsp;<\/td><\/tr><tr><td><strong>Mar 1, 2027<\/strong><\/td><td><br>Client Auth EKU removed from all public TLS certificates &nbsp;<\/td><td>Organizations using public certs for mTLS or server-to-server auth &nbsp;<\/td><td>Migrate to X9 PKI for TLS or Private PKI &nbsp;<\/td><td>Plan now &nbsp;<\/td><\/tr><tr><td><strong>Already done<\/strong><\/td><td><br>Default issuance moved to G2 hierarchies (Mar 8, 2023) &nbsp;<\/td><td>Most standard DigiCert customers &nbsp;<\/td><td>No action needed \u2014 next renewal auto-moves to G2\/G3 &nbsp;<\/td><td>Safe<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-this-isn-t-just-one-change-it-s-a-sequence\">This isn&#8217;t just One Change: It&#8217;s a Sequence<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The most pressing one is the G1 removal, although it is a subset of a larger cleanup of the public WebPKI. The following is the entire schedule:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-g1-root-removal-of-chrome-and-mozilla\">G1 Root Removal of Chrome and Mozilla<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Three particular roots are pulled: <strong>DigiCert Global Root CA, DigiCert Assured ID Root CA and DigiCert High Assurance EV Root CA.<\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Any active <a href=\"https:\/\/certera.com\/buy-ssl-certificates\">TLS certificates<\/a> that exclusively chain to these roots instantly lose their trust with Chrome and Firefox. No difference in certificates on G2 or G3 hierarchies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-g2-g3-intermediates-and-cross-signed-certificates-can-be-revoked\">The G2\/G3 intermediates and cross-signed certificates can be revoked<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">DigiCert withdraws many G2 and G3 intermediate CA certificates to provide non-TLS products such as <a href=\"https:\/\/certera.com\/smime-certificates\">S\/MIME<\/a> and <a href=\"https:\/\/certera.com\/code-signing\">Code Signing<\/a>, and two G5 cross-sign root certificates. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In case your chain of certificates relies upon any of these, validation is lost. This one traps those organisations that assumed that the G1 change was not relevant to them.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-client-authentication-eku-has-been-deleted-from-the-public-tls-certificates\">Client Authentication EKU has been deleted from the public TLS certificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/certera.com\/blog\/sectigo-and-digicert-to-remove-client-authentication-eku-from-public-ssl-tls-certificates\/\">DigiCert eliminates the clientAuth extended key usage<\/a> on all public TLS certs of all brands: DigiCert, GeoTrust, Thawte, RapidSSL, and Encryption Everywhere. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In case your organisation relies on public certificates to make <a href=\"https:\/\/certera.com\/blog\/what-is-mtls-authentication-mutual-tls\/\">mutual TLS<\/a> or server-server authentication, you should have a migration plan long before this date.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-s-actually-at-risk\">Who&#8217;s actually at Risk?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is where most organisations get blindsided. They check their primary domain, see it&#8217;s fine, and close the ticket. Then something breaks in a partner integration at 2 am on a Tuesday.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>You&#8217;re exposed if any of these describe your environment:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Active TLS certificates issued from a G1 root hierarchy that expire after April 15, 2026<\/li>\n\n\n\n<li>Custom trust stores, manually built CA bundles, or <a href=\"https:\/\/certera.com\/blog\/what-is-certificate-pinning-how-does-certificate-pinning-work\/\">certificate pinning<\/a> in internal applications or devices<\/li>\n\n\n\n<li>Network appliances, VPNs, mail gateways, load balancers, or IoT devices with hardcoded root trust that rarely get updated<\/li>\n\n\n\n<li>B2B integrations, reverse proxies, or machine-to-machine connections that validate the full certificate chain<\/li>\n\n\n\n<li>Legacy admin subdomains, staging environments, or partner portals that slip through normal renewal cycles<\/li>\n\n\n\n<li>Cross-signed compatibility workarounds put in place years ago and never revisited<\/li>\n\n\n\n<li>Standard websites renewed normally after March 2023 already on G2, <strong>no action needed<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The systems that cause the most painful outages aren&#8217;t the ones anyone is watching. They&#8217;re the secondary services, the older subdomains, the appliances in the server room that &#8220;just work&#8221; until they don&#8217;t. That&#8217;s exactly where G1 chains are most likely hiding.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-to-do-right-now\">What to do Right Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you follow these four steps in order, you are good to go.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-step-01-nbsp-run-a-full-certificate-inventory\">Step 01:&nbsp;Run a full certificate inventory<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Go beyond your main domain. Map every public certificate in use on admin portals, APIs, B2B endpoints, appliances, VPNs, mail gateways, and any service that uses a public cert. Assign a business and technical owner to each one.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-step-02-nbsp-trace-the-full-trust-chain\">Step 02:&nbsp;Trace the full trust chain<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The brand on the cert <a href=\"https:\/\/certera.com\/ssl\/geotrust\">GeoTrust<\/a>, <a href=\"https:\/\/certera.com\/ssl\/rapidssl\">RapidSSL<\/a>, <a href=\"https:\/\/certera.com\/ssl\/thawte\">Thawte<\/a> doesn&#8217;t tell you which root it chains to. You need to verify each deployment&#8217;s actual trust path. DigiCert publishes G1-to-G2 intermediate mappings to make this easier.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-step-03-nbsp-reissue-affected-certs-into-g2-or-g3\">Step 03:&nbsp;Reissue affected certs into G2 or G3<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For every G1 certificate expiring after April 15, reissue now.<\/strong> In most cases, you don&#8217;t need to generate a new private key. This is usually a reissue, not a full rebuild. Confirm with your product&#8217;s specific policy before you start.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-step-04-test-client-side-trust-dependencies\">Step 04: Test client-side trust dependencies<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Reissuing the server certificate is only half the job. Old devices, agents, and applications that expect the G1 root will still reject the new chain. Test compatibility on every client, integration, and endpoint that touches the updated certificate.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-certificate-is-no-longer-a-one-time-purchase\">A Certificate is no longer a One-time Purchase<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The G1 removal isn&#8217;t an isolated event. It is a part of a much greater change in how the web handles certificate trust. There are <a href=\"https:\/\/certera.com\/blog\/ca-b-approved-47-day-ssl-tls-validity-by-2029-how-to-prepare\/\">shorter maximum certificate lifespans<\/a> that are enforced. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/certera.com\/blog\/multi-perspective-issuance-corroboration-strengthening-certificate-validation-security\/\">Multi-perspective issuance checks<\/a> are already being rolled out. Single-purpose root hierarchies are emerging as the new norm in all major browser applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organisations that continue to consider SSL as a one-time buy and forget-about-it task are going to continue to be caught unawares each time one of these changes hits the ground. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ones who give actual visibility into their certificate infrastructure, with each cert owner knowing where it is deployed, which chain it is in, and when it is due to be renewed, and when it is due to be revoked, see every deadline as a regular working operation, not a crisis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is not a matter of not having a browser warning this year, but what you do before April 15. It is about developing the process that safeguards you in all the changes thereof.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusion\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This isn\u2019t just another certificate update. It\u2019s a wake-up call.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">April 15, 2026, won\u2019t break everything overnight. It will reveal the holes that you were unaware of: forgotten certificates, old systems, and unspoken dependencies that have not been accessed in years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those organisations that do so will consider it a normal migration. The delays of the ones? They will find the problem when users are faced with a security warning, and at this point, it is already affecting business.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-other-major-updates-of-2026\">Other Major Updates of 2026<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/certera.com\/blog\/dnssec-validation-for-ssl-certificates-ca-b-forum-ballot-sc-085-changes-in-march-2026\/\">DNSSEC Validation for SSL Certificates: CA\/B Forum Ballot SC-085 Changes in March 2026<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/certera.com\/blog\/sectigo-new-public-roots-and-issuing-cas-hierarchy-2025-migration-guide\/\">Sectigo New Public Roots and Issuing CAs Hierarchy<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/certera.com\/blog\/major-ssl-tls-certificate-changes-2026-every-website-owner-must-know\/\">Major SSL\/TLS Certificate Changes 2026: Everyone Should Know<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/certera.com\/blog\/47-day-ssl-tls-mandates-a-step-towards-transitioning-to-automation\/\">47\u2011Day SSL\/TLS Mandates: A Step Towards Transitioning to Automation<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>DigiCert G1 Retirement 2026: A Turning Point in Web PKI Evolution Mozilla and Google Chrome will revoke the G1 root certificates of DigiCert on April 15, 2026. When the certificate you are using TLS chains to one of those roots, the browsers immediately do not trust it. A security warning is shown to your users.<span class=\"morelink d-block mt-3\"><a href=\"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/\">Read More<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":4623,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18,5],"tags":[880,879],"class_list":["post-4622","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-encryption","category-ssl-certificate","tag-digicert-g1-root-removal","tag-digicert-g1-to-g2","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DigiCert G1 Root Distrust in Chrome and Firefox: What You Must Do<\/title>\n<meta name=\"description\" content=\"The End of DigiCert G1 Roots On April 15, 2026. Understand the Bigger Picture Behind DigiCert G1 Root Deprecation, timelines, actions &amp; more.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DigiCert G1 Root Distrust in Chrome and Firefox: What You Must Do\" \/>\n<meta property=\"og:description\" content=\"The End of DigiCert G1 Roots On April 15, 2026. Understand the Bigger Picture Behind DigiCert G1 Root Deprecation, timelines, actions &amp; more.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/\" \/>\n<meta property=\"og:site_name\" content=\"EncryptedFence by Certera - Web &amp; Cyber Security Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/certeraLLC\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-16T10:12:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-16T10:12:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2026\/04\/digicert-g1-root-cert-distrust.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"620\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:site\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/\"},\"author\":{\"name\":\"Janki Mehta\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\"},\"headline\":\"DigiCert G1 Root Removal 2026: What It Means, Risks &amp; Action Plan for Your TLS Infrastructure\",\"datePublished\":\"2026-04-16T10:12:19+00:00\",\"dateModified\":\"2026-04-16T10:12:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/\"},\"wordCount\":1251,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/digicert-g1-root-cert-distrust.webp\",\"keywords\":[\"DigiCert G1 Root Removal\",\"DigiCert G1 to G2\"],\"articleSection\":[\"Encryption\",\"SSL Certificate\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/#respond\"]}],\"copyrightYear\":\"2026\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/\",\"name\":\"DigiCert G1 Root Distrust in Chrome and Firefox: What You Must Do\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/digicert-g1-root-cert-distrust.webp\",\"datePublished\":\"2026-04-16T10:12:19+00:00\",\"dateModified\":\"2026-04-16T10:12:20+00:00\",\"description\":\"The End of DigiCert G1 Roots On April 15, 2026. Understand the Bigger Picture Behind DigiCert G1 Root Deprecation, timelines, actions & more.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/#primaryimage\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/digicert-g1-root-cert-distrust.webp\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/digicert-g1-root-cert-distrust.webp\",\"width\":960,\"height\":620,\"caption\":\"DigiCert G1 Root Deprecation 2026\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/certera.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DigiCert G1 Root Removal 2026: What It Means, Risks &amp; Action Plan for Your TLS Infrastructure\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"name\":\"EncryptedFence by Certera - Web & Cyber Security Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"alternateName\":\"Certera's EncryptedFence Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/certera.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\",\"name\":\"Certera\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"caption\":\"Certera\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/certeraLLC\\\/\",\"https:\\\/\\\/x.com\\\/certera_llc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/certera-llc\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\",\"name\":\"Janki Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"caption\":\"Janki Mehta\"},\"description\":\"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\\\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.\",\"sameAs\":[\"https:\\\/\\\/certerassl.com\\\/\"],\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/author\\\/certerabguser\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DigiCert G1 Root Distrust in Chrome and Firefox: What You Must Do","description":"The End of DigiCert G1 Roots On April 15, 2026. Understand the Bigger Picture Behind DigiCert G1 Root Deprecation, timelines, actions & more.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/","og_locale":"en_US","og_type":"article","og_title":"DigiCert G1 Root Distrust in Chrome and Firefox: What You Must Do","og_description":"The End of DigiCert G1 Roots On April 15, 2026. Understand the Bigger Picture Behind DigiCert G1 Root Deprecation, timelines, actions & more.","og_url":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/","og_site_name":"EncryptedFence by Certera - Web &amp; Cyber Security Blog","article_publisher":"https:\/\/www.facebook.com\/certeraLLC\/","article_published_time":"2026-04-16T10:12:19+00:00","article_modified_time":"2026-04-16T10:12:20+00:00","og_image":[{"width":960,"height":620,"url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2026\/04\/digicert-g1-root-cert-distrust.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_creator":"@certera_llc","twitter_site":"@certera_llc","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/#article","isPartOf":{"@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/"},"author":{"name":"Janki Mehta","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7"},"headline":"DigiCert G1 Root Removal 2026: What It Means, Risks &amp; Action Plan for Your TLS Infrastructure","datePublished":"2026-04-16T10:12:19+00:00","dateModified":"2026-04-16T10:12:20+00:00","mainEntityOfPage":{"@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/"},"wordCount":1251,"commentCount":0,"publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"image":{"@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2026\/04\/digicert-g1-root-cert-distrust.webp","keywords":["DigiCert G1 Root Removal","DigiCert G1 to G2"],"articleSection":["Encryption","SSL Certificate"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/#respond"]}],"copyrightYear":"2026","copyrightHolder":{"@id":"https:\/\/certera.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/","url":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/","name":"DigiCert G1 Root Distrust in Chrome and Firefox: What You Must Do","isPartOf":{"@id":"https:\/\/certera.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/#primaryimage"},"image":{"@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2026\/04\/digicert-g1-root-cert-distrust.webp","datePublished":"2026-04-16T10:12:19+00:00","dateModified":"2026-04-16T10:12:20+00:00","description":"The End of DigiCert G1 Roots On April 15, 2026. Understand the Bigger Picture Behind DigiCert G1 Root Deprecation, timelines, actions & more.","breadcrumb":{"@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/#primaryimage","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2026\/04\/digicert-g1-root-cert-distrust.webp","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2026\/04\/digicert-g1-root-cert-distrust.webp","width":960,"height":620,"caption":"DigiCert G1 Root Deprecation 2026"},{"@type":"BreadcrumbList","@id":"https:\/\/certera.com\/blog\/digicert-g1-root-removal-2026-what-it-means-what-actions-to-do\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/certera.com\/blog\/"},{"@type":"ListItem","position":2,"name":"DigiCert G1 Root Removal 2026: What It Means, Risks &amp; Action Plan for Your TLS Infrastructure"}]},{"@type":"WebSite","@id":"https:\/\/certera.com\/blog\/#website","url":"https:\/\/certera.com\/blog\/","name":"EncryptedFence by Certera - Web & Cyber Security Blog","description":"","publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"alternateName":"Certera's EncryptedFence Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/certera.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/certera.com\/blog\/#organization","name":"Certera","url":"https:\/\/certera.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","caption":"Certera"},"image":{"@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/certeraLLC\/","https:\/\/x.com\/certera_llc","https:\/\/www.linkedin.com\/company\/certera-llc\/"]},{"@type":"Person","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7","name":"Janki Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","caption":"Janki Mehta"},"description":"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.","sameAs":["https:\/\/certerassl.com\/"],"url":"https:\/\/certera.com\/blog\/author\/certerabguser\/"}]}},"_links":{"self":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/4622","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/comments?post=4622"}],"version-history":[{"count":2,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/4622\/revisions"}],"predecessor-version":[{"id":4626,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/4622\/revisions\/4626"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media\/4623"}],"wp:attachment":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media?parent=4622"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/categories?post=4622"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/tags?post=4622"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}