Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In July and August 2024, DigiCert revoked 83,267 TLS certificates affecting 6,807 customers after finding that a domain-control validation path did not meet certificate-issuance requirements. The emergency replacement deadline passed on August 3, 2024; it is not a current deadline. The incident concerned validation compliance, not a reported compromise of DigiCert’s certificate-signing keys.

What happened?

DigiCert discovered that one path in its domain-validation system could issue a certificate after a CNAME-based domain control validation that did not use the required format for a random value. DigiCert notified customers that affected certificates would be revoked. CISA warned that sites, services, and applications still using a revoked certificate could be disrupted.

The incident affected a particular validation path associated with DigiCert’s OEM validation process. DigiCert’s incident report says its CertCentral and CIS validation paths correctly validated domains and were not affected. The Mozilla-hosted incident report records 83,267 valid certificates in scope; the UAE Cyber Security Council’s July 31, 2024 advisory reports 6,807 affected customers. (DigiCert incident report and closure summary; UAE Cyber Security Council advisory)

Why were the certificates revoked?

For CNAME-based domain control validation, a certificate authority uses a random value in a DNS record to establish that the certificate requester controls the domain. DigiCert found that a service in its validation system did not automatically add the required underscore prefix to that value or verify that the prefix was present. As a result, the affected path could fail to perform validation in the format required for certificate issuance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

DigiCert linked the defect to the move from a monolithic validation system to separate services: a legacy behavior that added the underscore had not been consistently carried over. Later consolidation of random-value generation inadvertently corrected the missing prefix, but the incident report also identified broader engineering and compliance-review weaknesses. In particular, format requirements were not adequately checked, tests focused on workflow behavior rather than the value’s required format, and architecture changes lacked compliance sign-off. DigiCert’s closure summary records completed changes including centralized value generation, format checks, compliance participation in architecture review, and removal of infrequently used paths. (DigiCert incident report and closure summary)

The documented issue was certificate-validation non-compliance and a potential mis-issuance path. The reviewed incident records do not establish that attackers exploited the affected certificates or obtained private keys.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How many customers and certificates were affected?

The figures come from different sources and count different things: DigiCert’s incident report, hosted on Mozilla Bugzilla, gives the certificate count, while the UAE Cyber Security Council advisory gives the customer count. The advisory also says the issue affected approximately 0.4% of applicable domain validations; that percentage is not the share of all DigiCert certificates or customers.

Measure Reported figure Source and qualification
Valid certificates affected 83,267 DigiCert incident report hosted by Mozilla Bugzilla, 2024.
Customers affected 6,807 UAE Cyber Security Council advisory, July 31, 2024.
Applicable domain validations affected Approximately 0.4% DigiCert figure as reported in the UAE Cyber Security Council advisory, 2024; this is not a percentage of all certificates or customers.

What did customers have to do?

During the incident, CISA advised affected customers to check their DigiCert accounts, identify non-compliant certificates, and reissue or rekey them. CISA warned that relying on a revoked certificate could temporarily disrupt websites, services, and applications. (CISA: DigiCert Certificate Revocations)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For organizations managing many certificates, the operational lesson is to keep an inventory that identifies each certificate’s owner, service, and deployment dependencies, and to maintain a tested replacement and rollout process. A replacement is useful only if the teams responsible for the affected services can deploy it before the old certificate stops being trusted.

DigiCert’s current documentation says certificate revocation is permanent and cannot be undone. It advises replacing certificates before submitting an order-wide revocation request. That is general workflow guidance, not a restatement of the expired 2024 incident deadline. (DigiCert: Revoke certificates)

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When were the certificates revoked, and were they actually revoked?

Yes. The delayed-revocation record says DigiCert revoked all 83,267 affected certificates over five days, with the final deadline set for August 3, 2024, at 19:30 UTC. The schedule changed during the incident after discussions about operational impact and a court order involving a customer. The dates below are historical, not current response instructions. (DigiCert delayed-revocation updates)

Date Incident stage
July 29, 2024 DigiCert identified affected certificates and notified customers of its plan to revoke them.
July 30, 2024 CISA issued its alert about the non-compliance issue and possible service disruption.
July 31, 2024 CISA updated its alert with a revised deadline of 3:30 p.m. EDT that day.
August 3, 2024, 19:30 UTC Final revocation deadline in the delayed-revocation record; all 83,267 affected certificates were revoked within five days.

CISA’s warning captured the practical risk: “Revocation of these certificates may cause temporary disruptions to websites, services, and applications relying on these certificates for secure communication.” (CISA, July 30, 2024)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.