Support DigiCert G5 family as TLS issuance hierarchy will change from G2/G3
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 72/100
Research direction
Start with gems/aws-sdk-core/ca-bundle.crt and review the DigiCert G5 root and intermediate certificate information linked in the issue. Update the bundled certificates to support the new DigiCert TLS issuance hierarchy, then verify the bundle contains the required G5 certificates and does not remove existing coverage.
Written by the indexing model from the issue text.
Description
Describe the feature
Bundled certs in https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-core/ca-bundle.crt are very old. Based on https://knowledge.digicert.com/general-information/digicert-g5-root-and-intermediate-ca-certificate-update, from Oct. 15, 2026, DigiCert will change the default public TLS issuance hierarchy from the DigiCert Global G2 and G3 root hierarchies to the dedicated DigiCert G5 TLS root hierarchies.
Consequently, after October 15, there is a risk of connection failures to any non-AWS endpoints accessed via the AWS SDK that present a certificate chained to DigiCert G5.
Use Case
After October 15, there is a risk of connection failures to any non-AWS endpoints accessed via the AWS SDK that present a certificate chained to DigiCert G5.
Proposed Solution
No response
Other Information
No response
Acknowledgements
- I may be able to implement this feature request
- This feature might incur a breaking change
SDK version used
latest
Environment details (OS name and version, etc.)
any OS
- Dominant language
- Ruby
- Stars
- 3.7k
- Forks
- 1.2k
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 5
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from aws/aws-sdk-ruby
-
service-api
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
aws/aws-sdk-ruby#3395 · 1 comment ·
-
bug needs-triage
Difficulty 3/5 1-2 days Newbie friendliness 74/100
aws/aws-sdk-ruby#3419 ·
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 58/100
aws/aws-sdk-ruby#3393 · 1 comment ·
-
BedrockAgentCore: invoke_agent_runtime buffers entire response instead of streaming in real-time Opendocumentation
Difficulty 4/5 3-5 days Newbie friendliness 48/100
aws/aws-sdk-ruby#3348 · 6 comments · 1 reaction ·
-
cross-sdk feature-request
Difficulty 3/5 1-2 days Newbie friendliness 68/100
aws/aws-sdk-ruby#3313 · 5 comments ·
All issues in aws/aws-sdk-ruby
Similar issues
-
user-reported
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Kong/developer.konghq.com#7316 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
TheOdinProject/curriculum#31408 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
notch8/utk_knapsack#148 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Homebrew/homebrew-cask#288729 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100