Describe the feature
Bundled certs in https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-core/ca-bundle.crt are very old. Based on https://knowledge.digicert.com/general-information/digicert-g5-root-and-intermediate-ca-certificate-update, from Oct. 15, 2026, DigiCert will change the default public TLS issuance hierarchy from the DigiCert Global G2 and G3 root hierarchies to the dedicated DigiCert G5 TLS root hierarchies.
Consequently, after October 15, there is a risk of connection failures to any non-AWS endpoints accessed via the AWS SDK that present a certificate chained to DigiCert G5.
Use Case
After October 15, there is a risk of connection failures to any non-AWS endpoints accessed via the AWS SDK that present a certificate chained to DigiCert G5.
Proposed Solution
No response
Other Information
No response
Acknowledgements
SDK version used
latest
Environment details (OS name and version, etc.)
any OS
Describe the feature
Bundled certs in https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-core/ca-bundle.crt are very old. Based on https://knowledge.digicert.com/general-information/digicert-g5-root-and-intermediate-ca-certificate-update, from Oct. 15, 2026, DigiCert will change the default public TLS issuance hierarchy from the DigiCert Global G2 and G3 root hierarchies to the dedicated DigiCert G5 TLS root hierarchies.
Consequently, after October 15, there is a risk of connection failures to any non-AWS endpoints accessed via the AWS SDK that present a certificate chained to DigiCert G5.
Use Case
After October 15, there is a risk of connection failures to any non-AWS endpoints accessed via the AWS SDK that present a certificate chained to DigiCert G5.
Proposed Solution
No response
Other Information
No response
Acknowledgements
SDK version used
latest
Environment details (OS name and version, etc.)
any OS