Sectigo Certificate Chain Update - Required Client Action

Sectigo Certificate Chain Update - Required Client Action

Overview

Sectigo is migrating to a new certificate chain based on its updated Public Root and Issuing CA hierarchy. The new hierarchy has been incorporated into the trusted root stores of:
  1. Microsoft
  2. Apple
  3. Google / Chrome
  4. Mozilla
This change affects TLS certificate validation for clients connecting to our services.

Who Is Affected

Clients using outdated runtime environments or security libraries may encounter certificate validation errors on *.everbinding.nl and *.econnect.eu when the new chain is presented.
This particularly includes:
  1. Older Java versions
  2. Legacy JVM truststores
  3. Outdated OpenSSL versions
  4. Systems with manually managed or restricted trust stores
Modern platforms that regularly update their trusted root stores are generally not affected.

Temporary Workaround

To maintain compatibility during the transition period, we have implemented a temporary workaround.
Important:
  1. The workaround is not fully stable.
  2. In certain cases, the new certificate chain may still be presented.
  3. The workaround will be removed on the dates listed below.
Clients must update their environments before the workaround is disabled.

Required Actions

To ensure uninterrupted connectivity, complete one of the following before the deadline:

Option 1 – Install and Trust the New Certificates

Manually install and trust:
  1. The new Sectigo Public Root certificate
    1. Download Root Sectigo Public Server Authentication Root R46 (July 22, 2025)
  2. The corresponding intermediate (Issuing CA) certificate
Ensure these certificates are added to your system or application trust store.

Option 2 – Update Runtime and Security Libraries

Upgrade your environment to versions that natively trust the new Sectigo hierarchy, including:
  1. Updated Java runtime (JRE/JDK)
  2. Updated operating system root certificates
  3. Updated OpenSSL libraries
  4. Updated container base images
This is the recommended long-term solution.

Deadlines

The temporary compatibility workaround will be disabled on:
  1. Acceptance environment: April 1, 2026
  2. Production environment: May 1, 2026
After these dates, only the new certificate chain will be presented.

Clients who have not updated their trust configuration may experience TLS handshake failures or certificate validation errors.

Potential Error Messages

Depending on your platform, you may see errors such as:
  1. PKIX path building failed
  2. unable to find valid certification path to requested target
  3. certificate verify failed
  4. unknown CA
  5. TLS handshake failure
These indicate that the new Sectigo root or intermediate certificate is not trusted by your environment.
  1. Update your runtime or operating system to a currently supported version.
  2. Test connectivity in the acceptance environment before April 1, 2026.
  3. Promote changes to production before May 1, 2026.
Performing updates early reduces the risk of production outages.
    • Related Articles

    • Current status

      Language: EN / NL If an update occurs, more information can be found on the Release note page. If this is not the case, we would like to hear from the Support question There are currently no outages. History 14-02-2026 11:30 - 16-02-2026 11:00 ...
    • Trusted email sender

      At least you have a subscription form for this functionality "Basic"It's necessary because it's a paid service. Always make sure you have enough online.Togoed! If you are a supplier andSales invoicesTo your customersSendThen create an email receiver ...
    • Release Notes Platform

      Update 26.01.0 We would like to inform you that a platform update was deployed on Tuesday, February 10th, 2026, at 2:00 AM CET. This update was deployed without downtime. What’s New? Improved Look and Feel: More applications have been migrated to the ...
    • Connection to local folder via ClientConnector tool

      If your financial software doesn't have a built-in e-in e-invoicing functionality, but does support exporting to or importing from a local folder, we offer the ability to connect to a local folder. In this instruction page we discuss the design of ...
    • Setting environment and personal data

      As soon as you log in, this pop-up appears asking if you not only want to send e-invoices, but whether you want to be able to receive them. Because costs are charged for this, this is disabled by default. You can select per organization whether you ...