← Back

DigiCert Mass TLS Certificate Revocations (Domain Validation Bug)

In July 2024, DigiCert discovered that a subset of TLS certificates had been issued using a defective domain validation method. CA/Browser Forum baseline requirements mandate rapid revocation of mis-issued certificates, requiring DigiCert to revoke a large batch of certificates within hours.

Google Cloud was among the affected customers, requiring emergency certificate reissuance across its services. Website operators across the internet were forced to replace certificates under tight deadlines to avoid service disruptions from browser rejection of revoked certificates.