Skip to main content

Managing Trust: Handling Expiring Cross-Certificates in Legacy Systems

Problem

One or more Entrust Certificate Services cross-certificates will expire soon

Summary

One or more Entrust Certificate Services cross certificates are expiring soon. Cross-certificates are special purpose certificates issued between root Certificate Authorities or from root Certificate Authorities to issuing or subordinate Certificate Authorities that can be used to extend trust to older operating systems and other niche use cases.


One or more Entrust Certificate Services cross-certificates will expire soon. Cross-certificates are special-purpose certificates issued between root Certificate Authorities or from root Certificate Authorities to issuing or subordinate Certificate Authorities that can extend trust to older operating systems and other niche use cases.

The table below contains a list of certificates set to expire soon. We recommend updating your systems with the currently active intermediate or cross-chain certificate to avoid service disruption if you use these certificates in any production system:

- For TLS/SSL certificates, this can result in warning or error messages to your website's visitors.

- For S/MIME certificates, you may experience rejected or distrusted emails.

Issuer Name Subject Name Not After Serial Number Signature Algorithm
Entrust.net Certification Authority (2048) Entrust Certification Authority - L1K 2024-10-11 51ce00fe (Hexa) / 1372455166 (Decimal) SHA256
Entrust Root Certification Authority - G2 Entrust Certification Authority - L1K 2024-10-23 51d360ee (Hexa)/ 1372807406 (Decimal) SHA256
Entrust Root Certification Authority Entrust Certification Authority - L1M 2024-11-19 51D346E1 (Hexa)/1372800737 (Decimal) SHA256

Notes:

  • The above cross-certificates are for exceptional used cases and are not distributed through the normal Entrust certificate pickup process. This includes the certificate chain provided through our pickup pages, the ECS REST API, and our ACMEv2 service.
  • We recommend that you install the entire chain provided by Entrust when you obtain your end entity certificates and monitor the use of cross-certificates (if applicable) using appropriate certificate lifecycle management tools.
  • Customers configuring their systems to use the cross-certificate should review their systems and ensu re that they are updated as needed to ensure uninterrupted service.