DigiCert

Last updated
DigiCert, Inc.
Company type Private company
Industry Internet security, Public key infrastructure, IoT security
Founded2003;21 years ago (2003)
Headquarters
Lehi, Utah, U.S.
Number of locations
12
Area served
Worldwide
Key people
Number of employees
1,000+
Subsidiaries CyberTrust
GeoTrust
QuoVadis
RapidSSL
Thawte
Mocana
DNS Made Easy
Website www.digicert.com

DigiCert, Inc. is a digital security company headquartered in Lehi, Utah. [1] DigiCert provides public key infrastructure (PKI) and validation required for issuing digital certificates or TLS/SSL certificates, acting as a certificate authority (CA) and trusted third party.

Contents

History

Example of a DigiCert issued wildcard certificate for *.wikipedia.org Firefox 89 AboutCertificate screenshot.png
Example of a DigiCert issued wildcard certificate for *.wikipedia.org

DigiCert was founded by Ken Bretschneider in 2003. [2] [3] Bretschneider served as CEO and chairman of the board until 2012 when he was appointed Executive chairman and Nicholas Hales became CEO. [4] In 2016, the company named John Merrill CEO, [5] who left the company in 2022. [6]

In 2005, DigiCert became a founding member of the CA/Browser Forum. [7]

In 2007, DigiCert partnered with Microsoft to develop the industry's first multi-domain (SAN) certificate. [8] [2]

In 2015, DigiCert acquired the CyberTrust Enterprise SSL business from Verizon Enterprise Solutions, becoming the world's second-largest certificate authority for high-assurance or extended validation (EV) TLS/SSL certificates. [9]

On August 28, 2015, private equity firm Thoma Bravo acquired a majority stake in DigiCert, with TA Associates holding a minority share. [10]

In 2017, DigiCert acquired the TLS/SSL and PKI businesses from Symantec, including brands GeoTrust, RapidSSL (part of GeoTrust), Thawte and Verisign [11] The acquisition resulted from questions first raised in 2015 by web browsers Google and Mozilla about the authenticity of certificates issued by Symantec, which represented one-third of all TLS/SSL certificates on the web. [12] [13] In September 2017, Google and Mozilla announced they would "... reduce, and ultimately remove, trust in Symantec's Root Keys in order to uphold users’ security and privacy when browsing the web." The final distrust deadline for certificates chaining to Symantec roots was set for October 2018. [14] Symantec agreed to transfer its certificate business to its top TLS/SSL competitor, DigiCert, whose roots were trusted by browsers. [15] In December 2017, DigiCert began issuing free replacements for all distrusted certificates from Symantec, GeoTrust, RapidSSL, Thawte, and VeriSign. By Oct. 2018, the company had revalidated more than 550,000 organizational identities and issued more than 5 million replacement certificates for affected customers. [16]

In 2018, DigiCert acquired QuoVadis, a trust service provider (TSP) headquartered in Switzerland offering qualified digital certificates, PKI services, and PrimoSign electronic signature software. [17] Qualified digital certificates from QuoVadis (now backed by DigiCert) comply with eIDAS, a set of EU standards for electronic transactions requiring legal proof of authentication. The EU Payment Services Directive mandated that banks and other financial institutions operating in Europe begin using qualified digital certificates by Jun. 2019. According to DigiCert, "... the QuoVadis acquisition aligns with the company's vision of providing globally dispersed and robust PKI-based solutions with local support." [18]

In 2019, the company announced a new R&D division called DigiCert Labs, "... an initiative dedicated to researching and developing innovative approaches to security challenges." [19] DigiCert Labs will collaborate with other enterprise labs – including Microsoft Research, Utimaco, ISARA, and Gemalto – and make grants to universities for the study of topics related to authentication, data integrity, encryption and identity. Initial research projects will focus on post-quantum cryptography and machine learning. [20] In 2019, DigiCert also launched the first post-quantum computing tool kit. [21]

In 2019, Clearlake Capital Group, L.P., a leading private investment firm, and TA Associates, an existing investor, reached an agreement to make a strategic growth investment in DigiCert. As part of the transaction, Clearlake and TA Associates become equal partners in the company. [22] [23]

In January 2022, DigiCert acquired IoT security company Mocana. [24] In June 2022, the company acquired DNS Made Easy, a DNS services provider. [25]

On October 19, 2022, DigiCert named Dr. Amit Sinha as CEO and board member. [6] Amit had previously led technology and innovation at cybersecurity leader Zscaler the previous 12 years.

Industry Involvement

DigiCert is involved in industry and regulatory groups and projects, [26] [27] [28] such as:

Criticism

DigiCert Inc. is not related to Digicert Sdn. Bhd, a Malaysian-based certification authority that issues certificates with weak keys and had its trust revoked by web browsers. [40] [41] [42]

In 2019, Google security researcher Scott Helme found approximately a million dollars worth of extended verification certificates that needed to be revoked due to faulty data, a significant portion of which were DigiCert certificates. [43]

In 2022, DigiCert was condemned by Scott Helme for pushing [44] QWAC scheme of certificate similar to EV certificates that undermined trust in certificates. [45] [46] [47]

Related Research Articles

Transport Layer Security (TLS) is a cryptographic protocol designed to provide communications security over a computer network. The protocol is widely used in applications such as email, instant messaging, and voice over IP, but its use in securing HTTPS remains the most publicly visible.

<span class="mw-page-title-main">Public key infrastructure</span> System that can issue, distribute and verify digital certificates

A public key infrastructure (PKI) is a set of roles, policies, hardware, software and procedures needed to create, manage, distribute, use, store and revoke digital certificates and manage public-key encryption. The purpose of a PKI is to facilitate the secure electronic transfer of information for a range of network activities such as e-commerce, internet banking and confidential email. It is required for activities where simple passwords are an inadequate authentication method and more rigorous proof is required to confirm the identity of the parties involved in the communication and to validate the information being transferred.

In cryptography, a public key certificate, also known as a digital certificate or identity certificate, is an electronic document used to prove the validity of a public key. The certificate includes the public key and information about it, information about the identity of its owner, and the digital signature of an entity that has verified the certificate's contents. If the device examining the certificate trusts the issuer and finds the signature to be a valid signature of that issuer, then it can use the included public key to communicate securely with the certificate's subject. In email encryption, code signing, and e-signature systems, a certificate's subject is typically a person or organization. However, in Transport Layer Security (TLS) a certificate's subject is typically a computer or other device, though TLS certificates may identify organizations or individuals in addition to their core role in identifying devices. TLS, sometimes called by its older name Secure Sockets Layer (SSL), is notable for being a part of HTTPS, a protocol for securely browsing the web.

<span class="mw-page-title-main">Root certificate</span> Certificate identifying a root authority

In cryptography and computer security, a root certificate is a public key certificate that identifies a root certificate authority (CA). Root certificates are self-signed and form the basis of an X.509-based public key infrastructure (PKI). Either it has matched Authority Key Identifier with Subject Key Identifier, in some cases there is no Authority Key identifier, then Issuer string should match with Subject string. For instance, the PKIs supporting HTTPS for secure web browsing and electronic signature schemes depend on a set of root certificates.

In cryptography, a certificate authority or certification authority (CA) is an entity that stores, signs, and issues digital certificates. A digital certificate certifies the ownership of a public key by the named subject of the certificate. This allows others to rely upon signatures or on assertions made about the private key that corresponds to the certified public key. A CA acts as a trusted third party—trusted both by the subject (owner) of the certificate and by the party relying upon the certificate. The format of these certificates is specified by the X.509 or EMV standard.

<span class="mw-page-title-main">Gen Digital</span> Multinational software company

Gen Digital Inc. is a multinational software company co-headquartered in Tempe, Arizona and Prague, Czech Republic. The company provides cybersecurity software and services. Gen is a Fortune 500 company and a member of the S&P 500 stock-market index. The company also has development centers in Pune, Chennai and Bangalore. Its portfolio includes Norton, Avast, LifeLock, Avira, AVG, ReputationDefender, and CCleaner.

CyberTrust was a security services company formed in Virginia in November 2004 from the merger of TruSecure and Betrusted. Betrusted previously acquired GTE Cybertrust. Cybertrust acquired a large stake in Ubizen, a European security services firm based in Belgium, to become one of the largest information security firms in the world. It was acquired by Verizon Business in 2007. In 2015, the CyberTrust root certificates were acquired by DigiCert, Inc., a leading global Certificate Authority (CA) and provider of trusted identity and authentication services.

Thawte Consulting is a certificate authority (CA) for X.509 certificates. Thawte was founded in 1995 by Mark Shuttleworth in South Africa. As of December 30, 2016, its then-parent company, Symantec Group, was collectively the third largest public CA on the Internet with 17.2% market share.

Code signing is the process of digitally signing executables and scripts to confirm the software author and guarantee that the code has not been altered or corrupted since it was signed. The process employs the use of a cryptographic hash to validate authenticity and integrity. Code signing was invented in 1995 by Michael Doyle, as part of the Eolas WebWish browser plug-in, which enabled the use of public-key cryptography to sign downloadable Web app program code using a secret key, so the plug-in code interpreter could then use the corresponding public key to authenticate the code before allowing it access to the code interpreter's APIs.

GeoTrust is a digital certificate provider. The GeoTrust brand was bought by Symantec from Verisign in 2010, but agreed to sell the certificate business in August 2017 to private equity and growth capital firm Thoma Bravo LLC. GeoTrust was the first certificate authority to use the domain-validated certificate method which accounts for 70 percent of all SSL certificates on the Internet. By 2006, GeoTrust was the 2nd largest certificate authority in the world with 26.7 percent market share according to independent survey company Netcraft.

GlobalSign is a certificate authority and a provider of internet identity and security products. As of January 2015, Globalsign was the 4th largest certificate authority in the world, according to Netcraft.

The Certification Authority Browser Forum, also known as the CA/Browser Forum, is a voluntary consortium of certification authorities, vendors of Internet browser and secure email software, operating systems, and other PKI-enabled applications that promulgates industry guidelines governing the issuance and management of X.509 v.3 digital certificates that chain to a trust anchor embedded in such applications. Its guidelines cover certificates used for the SSL/TLS protocol and code signing, as well as system and network security of certificate authorities.

StartCom was a certificate authority founded in Eilat, Israel, and later based in Beijing, China, that had three main activities: StartCom Enterprise Linux, StartSSL and MediaHost. StartCom set up branch offices in China, Hong Kong, the United Kingdom and Spain. Due to multiple faults on the company's end, all StartCom certificates were removed from Mozilla Firefox in October 2016 and Google Chrome in March 2017, including certificates previously issued, with similar removals from other browsers expected to follow.

The Transport Layer Security (TLS) protocol provides the ability to secure communications across or inside networks. This comparison of TLS implementations compares several of the most notable libraries. There are several TLS implementations which are free software and open source.

DigiNotar was a Dutch certificate authority owned by VASCO Data Security International, Inc.

<span class="mw-page-title-main">Wildcard certificate</span> Public key certificate which can be used with multiple subdomain of a domain

A Public key certificate which uses an asterisk * in its domain name fragment is called a Wildcard certificate. Through the use of *, a single certificate may be used for multiple sub-domains. It is commonly used for transport layer security in computer networking.

<span class="mw-page-title-main">Certificate Authority Security Council</span> Organization

The Certificate Authority Security Council (CASC) is a multi-vendor industry advocacy group created to conduct research, promote Internet security standards and educate the public on Internet security issues.

Certificate Transparency (CT) is an Internet security standard for monitoring and auditing the issuance of digital certificates.

The Enrollment over Secure Transport, or EST is a cryptographic protocol that describes an X.509 certificate management protocol targeting public key infrastructure (PKI) clients that need to acquire client certificates and associated certificate authority (CA) certificates. EST is described in RFC 7030. EST has been put forward as a replacement for SCEP, being easier to implement on devices already having an HTTPS stack. EST uses HTTPS as transport and leverages TLS for many of its security attributes. EST has described standardized URLs and uses the well-known Uniform Resource Identifiers (URIs) definition codified in RFC 5785.

Trustico is a dedicated SSL certificate provider, They are headquartered in the United Kingdom.

References

  1. Editorial (2022-05-06). "Meet Digicert A Leading Global Provider Of Digital Trust Enabling Individuals And Businesses To Engage Online With The Confidence". Tech Company News. Retrieved 2023-03-29.
  2. 1 2 "History of Innovation | DigiCert". www.digicert.com. Retrieved 2023-01-27.
  3. Anstey, Tom (2018). "Interview - Ken Bretschneider and Josh Shipley" (PDF). Attractions Management. 2018 (4): 35.
  4. “Utah’s DigiCert reorganizes its management”. The Salt Lake Tribune . Retrieved 2019-02-28.
  5. “DigiCert names CEO”. Daily Herald. Retrieved 2019-02-28.
  6. 1 2 "DigiCert Appoints Industry Veteran Amit Sinha as Chief Executive Officer". www.prnewswire.com. 2022-10-19. Retrieved 2022-10-24.
  7. 1 2 "Members". CAB Forum. Retrieved 2023-01-27.
  8. "DigiCert Fact Sheet" (PDF). digicert.com.
  9. “DigiCert Acquires Verizon Enterprise SSL Business”. DigiCert.com. Retrieved 2019-03-01.
  10. Sean Michael Kerner (2015-08-28). "Thoma Bravo Invests in Security Firm DigiCert". Eweek.com. Retrieved 2015-12-25.
  11. Raymond, Art (3 August 2017). "Lehi's DigiCert swallows web security competitor in $1 billion deal". Deseret News. Retrieved 21 May 2020.
  12. Sharwood, Simon. “Symantec offloads its certs and web security biz to DigiCert”. The Register . Retrieved 2019-03-05.
  13. Constantin, Lucian. “To punish Symantec, Google may distrust a third of the web’s SSL certificates”. Computerworld . Retrieved 2019-03-05.
  14. “Chrome’s Plan to Distrust Symantec Certificates”. Google . Retrieved 2019-03-05.
  15. "DigiCert Closes Acquisition of Symantec's Website SSL Security Unit". eWeek . Retrieved 2019-03-11.
  16. "DigiCert works with its customers and partners to successfully move past Google's distrust of Symantec TLS certificates". PR Newswire (Press release). Retrieved 2019-03-01.
  17. Kent, Jonathan (2018-10-31). "QuoVadis to be sold to US firm DigiCert". www.royalgazette.com. Retrieved 2022-08-24.
  18. Barker, Sara. “DigiCert’s QuoVadis acquisition extends PKI expertise in Europe”. SecurityBrief EMEA. Retrieved 2019-03-05.
  19. “DigiCert Labs to innovate new security technologies that address emerging threats through collaboration with academic and industry research”. PR Newswire . Retrieved 2019-02-28.
  20. Barker, Sara. “DigiCert Labs to research postquantum cryptography and ML”. SecurityBrief EMEA. Retrieved 2019-02-28.
  21. "DigiCert Announces Post-Quantum Computing Tool Kit | DigiCert.com". www.digicert.com. Retrieved 2023-01-27.
  22. "News | TA". TA Associates. Retrieved 2019-07-16.
  23. "CLEARLAKE CAPITAL GROUP AND TA ASSOCIATES TO MAKE A STRATEGIC GROWTH INVESTMENT IN DIGICERT". Clearlake Capital. 2019-07-09. Retrieved 2019-07-16.
  24. Sawers, Paul (13 January 2022). "DigiCert acquires Mocana to bolster IoT security". VentureBeat. Retrieved 27 January 2022.
  25. Graham, Patrick (2022-06-09). "DigiCert Acquires DNS Made Easy". www.themiddlemarket.com. Retrieved 2022-08-24.
  26. "Industry Partnerships | DigiCert.com". www.digicert.com. Retrieved 2023-06-06.
  27. "DigiCert Company Culture". www.digicert.com. Retrieved 2023-06-06.
  28. News, Industry (2020-05-22). "DigiCert named 2020 Global Company of the Year in TLS certificate market by Frost & Sullivan". Help Net Security. Retrieved 2023-06-06.{{cite web}}: |last= has generic name (help)
  29. ThePKIGuy (2020-05-19). "The PKI Guy talks standards with Dean Coclin, chair of the ASC X9 PKI study group". PKI Solutions LLC. Retrieved 2023-06-06.
  30. Frazier, Ambria (2019-12-04). "ASC X9 Revives PKI Working Group To Address New Public Key Infrastructure Needs". Accredited Standards Committee X9. Retrieved 2023-06-06.
  31. "DigiCert selected to provide Root CA for AeroMACS". Datacentre Solutions. 2018-03-08. Retrieved 2023-06-06.
  32. "APWG | DigiCert" . Retrieved 2023-06-06.
  33. "DigiCert Root CA First Approved for Matter Device Attestation by Connectivity Standards Alliance | DigiCert". www.digicert.com. Retrieved 2023-06-06.
  34. https://www.digicert.com/content/dam/digicert/pdfs/ci-plus-tv-case-study.pdf
  35. kgwynn. "Member List". DirectTrust. Retrieved 2023-06-06.
  36. Inc, DigiCert. "DigiCert and Eonti Selected by the Western Canadian NG9-1-1 Network Operator to Secure the Next Generation 9-1-1 Systems". www.prnewswire.com (Press release). Retrieved 2023-06-06.{{cite press release}}: |last= has generic name (help)
  37. DigiCert. "DigiCert Joins NIST Consortium on Effective TLS Server Certificate Management". DigiCert. Retrieved 2023-06-06.
  38. "NCCoE Announces Technology Collaborators for the Migration to Post-Quantum Cryptography Project | NCCoE". www.nccoe.nist.gov. 15 July 2022. Retrieved 2023-06-06.
  39. "SAE International Hires World-Class Contractor Team for EV Charging Public Key Infrastructure Cooperative Research Project". www.sae.org. Retrieved 2023-06-06.
  40. "SSL Certificate Support - Entrust, Inc". Entrust.net. Retrieved 2015-12-25.
  41. Revoking Trust in DigiCert Sdn. Bhd Intermediate Certificate Authority, Mozilla. "DigiCert Sdn. Bhd is a Malaysian subordinate CA under Entrust and Verizon (GTE CyberTrust). It bears no affiliation whatsoever with the US-based corporation DigiCert, Inc., which is a member of Mozilla's root program."
  42. Microsoft Security Advisory (2641690) "DigiCert Sdn. Bhd is not affiliated with the corporation DigiCert, Inc., which is a member of the Microsoft Root Certificate Program."
  43. Helme, Scott (11 September 2019). "Extended Validation not so... extended? How I revoked $1,000,000 worth of EV certificates!". Archived from the original on 2019-09-11. Retrieved 2022-03-24.
  44. Helme, Scott (4 January 2022). "If it looks like a duck, swims like a duck, and QWACs like a duck, then it's probably an EV Certificate" . Retrieved 24 March 2022.
  45. "Mozilla and the EFF publish letter about the danger of Article 45.2 | The Mozilla Blog". blog.mozilla.org. Retrieved 2022-03-24.
  46. "Experts urge EU not to force insecure certificates in web browsers". BleepingComputer. Retrieved 2022-03-24.
  47. Callas, Alexis Hancock and Jon (2022-02-09). "What the Duck? Why an EU Proposal to Require "QWACs" Will Hurt Internet Security". Electronic Frontier Foundation. Retrieved 2022-03-24.