With the network change from Akami to Cloudflare, authorize.net has set up a (somewhat confusing) FAQ that tells us to update a certificate.
Do we also need to update the certificate if we're using the official PHP SDK API from the Github repository?
There's a cert.pem file in /lib/ssl, which does contain a couple of Entrust certificates, which is the same company for which the new certificate should be installed, so it might be affected by the change. Or not. Nobody really tells us.
There's also an open issue since November 2019 on the Github tracker regarding this, but no official answer has been given so far.
Maybe someone here will see this and can give a definitive answer.
I did check the certificates in the cert.pem file one by one, and all seem to be valid for 2026+, so it might be ok. But maybe not, some official answer would be really appreciated.
01-16-2020 10:54 AM
I also am concerned but when I opened the cert.pem file in the- authorize_net_sdk_php/lib/ssl directory that file has many many certificates on it. See here-
##
## Bundle of CA Root Certificates
##
## Certificate data from Mozilla as of: Wed Mar 7 04:12:06 2018 GMT
##
## This is a bundle of X.509 certificates of public Certificate Authorities
## (CA). These were automatically extracted from Mozilla's root certificates
## file (certdata.txt). This file can be found in the mozilla source tree:
## https://hg.mozilla.org/releases/mozilla-release/raw-file/default/security/nss/lib/ckfw/builtins/cert...
##
## It contains the certificates in PEM format and therefore
## can be directly used with curl / libcurl / php_curl, or with
## an Apache+mod_ssl webserver for SSL client authentication.
## Just configure this file as the SSLCACertificateFile.
##
## Conversion done with mk-ca-bundle.pl version 1.27.
## SHA256: 704f02707ec6b4c4a7597a8c6039b020def11e64f3ef0605a9c3543d48038a57
##
GlobalSign Root CA
==================
GlobalSign Root CA - R2
=======================
Verisign Class 3 Public Primary Certification Authority - G3
============================================================
Entrust.net Premium 2048 Secure Server CA
=========================================
Baltimore CyberTrust Root
=========================
AddTrust External Root
======================
Entrust Root Certification Authority
====================================
GeoTrust Global CA
==================
GeoTrust Universal CA
=====================
GeoTrust Universal CA 2
=======================
Visa eCommerce Root
===================
Comodo AAA Services root
========================
QuoVadis Root CA
================
QuoVadis Root CA 2
==================-
QuoVadis Root CA 3
==================
Security Communication Root CA
==============================
Sonera Class 2 Root CA
======================
XRamp Global CA Root
====================
Go Daddy Class 2 CA
===================
Starfield Class 2 CA
====================
Taiwan GRCA
===========
DigiCert Assured ID Root CA
===========================
DigiCert Global Root CA
=======================
DigiCert High Assurance EV Root CA
==================================
Certplus Class 2 Primary CA
===========================
DST Root CA X3
==============
SwissSign Gold CA - G2
======================
SwissSign Silver CA - G2
========================
GeoTrust Primary Certification Authority
========================================
thawte Primary Root CA
======================
VeriSign Class 3 Public Primary Certification Authority - G5
============================================================
SecureTrust CA
==============
Secure Global CA
================
COMODO Certification Authority
==============================
Network Solutions Certificate Authority
=======================================
COMODO ECC Certification Authority
==================================
OISTE WISeKey Global Root GA CA
===============================
Certigna
========
Deutsche Telekom Root CA 2
==========================
Cybertrust Global Root
======================
ePKI Root Certification Authority
=================================
certSIGN ROOT CA
================
GeoTrust Primary Certification Authority - G3
=============================================
thawte Primary Root CA - G3
===========================
GeoTrust Primary Certification Authority - G2
=============================================
VeriSign Universal Root Certification Authority
===============================================
VeriSign Class 3 Public Primary Certification Authority - G4
============================================================
NetLock Arany (Class Gold) Főtanúsítvány
========================================
Staat der Nederlanden Root CA - G2
==================================
Hongkong Post Root CA 1
=======================
SecureSign RootCA11
===================
Microsec e-Szigno Root CA 2009
==============================
GlobalSign Root CA - R3
=======================
Autoridad de Certificacion Firmaprofesional CIF A62634068
=========================================================
Chambers of Commerce Root - 2008
================================
Global Chambersign Root - 2008
==============================
Go Daddy Root Certificate Authority - G2
========================================
Starfield Root Certificate Authority - G2
=========================================
Starfield Services Root Certificate Authority - G2
==================================================
AffirmTrust Commercial
======================
AffirmTrust Networking
======================
AffirmTrust Premium
===================
AffirmTrust Premium ECC
=======================
Certum Trusted Network CA
=========================
TWCA Root Certification Authority
=================================
Security Communication RootCA2
==============================
EC-ACC
======
Hellenic Academic and Research Institutions RootCA 2011
=======================================================
Actalis Authentication Root CA
==============================
Trustis FPS Root CA
===================
Buypass Class 2 Root CA
=======================
Buypass Class 3 Root CA
=======================
T-TeleSec GlobalRoot Class 3
============================
EE Certification Centre Root CA
===============================
D-TRUST Root Class 3 CA 2 2009
==============================
D-TRUST Root Class 3 CA 2 EV 2009
=================================
CA Disig Root R2
================
ACCVRAIZ1
=========
TWCA Global Root CA
===================
TeliaSonera Root CA v1
======================
E-Tugra Certification Authority
===============================
T-TeleSec GlobalRoot Class 2
============================
Atos TrustedRoot 2011
=====================
QuoVadis Root CA 1 G3
====================
QuoVadis Root CA 2 G3
=====================
QuoVadis Root CA 3 G3
=====================
DigiCert Assured ID Root G2
===========================
DigiCert Assured ID Root G3
===========================
DigiCert Global Root G2
=======================
DigiCert Global Root G3
=======================
DigiCert Trusted Root G4
========================
COMODO RSA Certification Authority
==================================
USERTrust RSA Certification Authority
=====================================
USERTrust ECC Certification Authority
=====================================
GlobalSign ECC Root CA - R4
===========================
GlobalSign ECC Root CA - R5
===========================
Staat der Nederlanden Root CA - G3
==================================
Staat der Nederlanden EV Root CA
================================
IdenTrust Commercial Root CA 1
==============================
IdenTrust Public Sector Root CA 1
=================================
Entrust Root Certification Authority - G2
=========================================
Entrust Root Certification Authority - EC1
==========================================
CFCA EV ROOT
============
TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı H5
====================================================
Certinomis - Root CA
====================
OISTE WISeKey Global Root GB CA
===============================
SZAFIR ROOT CA2
===============
Certum Trusted Network CA 2
===========================
Hellenic Academic and Research Institutions RootCA 2015
=======================================================
Hellenic Academic and Research Institutions ECC RootCA 2015
===========================================================
Certplus Root CA G1
===================
Certplus Root CA G2
===================
OpenTrust Root CA G1
====================
OpenTrust Root CA G2
====================
OpenTrust Root CA G3
====================
ISRG Root X1
============
AC RAIZ FNMT-RCM
================
Amazon Root CA 1
================
Amazon Root CA 2
================
Amazon Root CA 3
================
Amazon Root CA 4
================
LuxTrust Global Root 2
======================
TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1
=============================================
GDCA TrustAUTH R5 ROOT
======================
TrustCor RootCert CA-1
======================
TrustCor RootCert CA-2
======================
TrustCor ECA-1
==============
SSL.com Root Certification Authority RSA
========================================
SSL.com Root Certification Authority ECC
========================================
SSL.com EV Root Certification Authority RSA R2
==============================================
SSL.com EV Root Certification Authority ECC
===========================================
10-03-2024 08:08 AM