Important Notice: Upcoming Certificate Chain Update for CardinalTrusted Endpoints

Scheduled Maintenance Report for CardinalCommerce

In progress

Scheduled maintenance is currently in progress. We will provide updates as necessary.
Posted Feb 24, 2026 - 16:00 EST

Scheduled

This notice is to inform you of an upcoming security certificate update for certain CardinalTrusted API endpoints.

This update includes a change to the certificate trust chain (root and intermediate certificates), not just a routine certificate renewal. As a result, some customers may need to take action to ensure uninterrupted connectivity.

What is changing:
• The TLS certificate chain used by select CardinalTrusted endpoints is being updated.
• The root and intermediate certificate authorities will change as part of this update.

What you may need to do:
• If your systems validate certificates using a custom trust store (for example, pinning or explicitly trusting certificate authorities), you may need to:
• Add the new root and intermediate certificates to your trust store before the change takes effect.
If you rely on standard operating system or JVM trust stores, no action is typically required.

What is not changing:
• There are no API behavior changes.
• There are no endpoint URL changes.
• This notice is separate from other certificate expiration or renewal messages you may have received.

Timing:/
The certificate update will be deployed in stages:
• Staging: Tuesday, March 31, 2026
• Production: Thursday, April 3, 2026 at 10:00 AM ET

Need help or unsure if you are impacted?

If you are uncertain whether this change affects your integration, or if you require clarification for your specific configuration, please open a Support ticket. Our team will work directly with you to ensure a smooth transition.

EXPIRING CERTIFICATES:

STAG:
Common Name (CN): cas.mtls.api.cardinaltrusted.com
Serial Number: 06:97:e8:7f:18:d5:12:c2:cf:e3:9b:99:3f:3e:75:43
Date of Replacement: 03/31/2026
Date of Expiry: 04/14/2026

Common Name (CN): cas.api.cardinaltrusted.com
Serial Name: 0c:1f:9b:be:08:ea:3e:4e:0c:d2:bf:98:58:f2:bd:a2
Date of Replacement: 03/31/2026
Date of Expiry: 04/14/2026

PROD:
Common Name (CN): mtls.api.cardinaltrusted.com
Serial Number: 05:62:c2:17:d1:c8:cf:cd:a0:ec:6c:e5:1b:ea:c8:d5
Date of Replacement: 04/03/2026
Date of Expiry: 04/14/2026

Common Name (CN): api.cardinaltrusted.com
Serial Number: 0b:22:a2:7f:2b:78:22:7f:a4:e0:9a:9d:29:99:6b:6d
Date of Replacement: 04/03/2026
Date of Expiry: 04/14/2026

Intermediate CA:
Common Name (CN): DigiCert SHA2 Secure Server CA
Serial Number: 02:74:2e:aa:17:ca:8e:21:c7:17:bb:1f:fc:fd:0c:a0

ROOT CA:
Common Name (CN): DigiCert Global Root CA
Serial Number: 08:3b:e0:56:90:42:46:b1:a1:75:6a:c9:59:91:c7:4a

NEW CERTIFICATES:

STAG:
Common Name (CN): cas.mtls.api.cardinaltrusted.com
Serial Number: 0e:b9:f0:c0:86:41:5d:c5:8e:0d:62:3f:27:ff:3d:27
Date of Replacement: 03/31/2026
Date of Expiry: 01/27/2027

Common Name (CN): cas.api.cardinaltrusted.com
Serial Number: 0e:f5:f4:6e:29:d4:06:92:38:02:c6:60:fd:86:69:8d
Date of Replacement: 03/31/2026
Date of Expiry: 01/26/2027

PROD:
Common Name (CN): mtls.api.cardinaltrusted.com
Serial Number: 0e:27:57:03:5c:8a:ae:96:c6:99:c9:6c:f2:80:a1:0e
Date of Replacement: 04/03/2026
Date of Expiry: 02/08/2027

Common Name (CN): api.cardinaltrusted.com
Serial Number: 0b:be:7b:52:df:89:52:c2:03:2e:56:d6:fd:79:9a:97
Date of Replacement: 04/03/2026
Date of Expiry: 02/08/2027

Intermediate CA:
Common Name (CN): DigiCert Global G2 TLS RSA SHA256 2020 CA1
Serial Number: 0c:f5:bd:06:2b:56:02:f4:7a:b8:50:2c:23:cc:f0:66

Root CA:
Common Name: DigiCert Global Root G2
Serial Number: 03:3a:f1:e6:a7:11:a9:a0:bb:28:64:b1:1d:09:fa:e5

Should you have any questions or concerns regarding this notice, please reach out to our support team at Support@cardinalcommerce.com.
Posted Feb 24, 2026 - 15:56 EST
This scheduled maintenance affects: Cardinal Consumer Authentication (3DS), Cardinal API, and Cardinal Hybrid API.