Overview
To enhance security and reliability, Databricks is updating the trusted TLS Certificate Authorities (CAs) that issue certificates for our public-facing websites and API endpoints. This change ensures continued compliance with industry best practices and improved resilience.
New Certificate Authorities - Databricks certificates are being migrated to the following trusted CAs:
- Let’s Encrypt
- Google Trust Services
- AWS Certificate Manager
- DigiCert
Who Is Not Impacted
If you use any supported browsers, or a client that already trusts the root and intermediate certificates from all of the CAs listed above, you do not need to take any action.
To confirm, you can test your client connectivity using the links below. If your client connects without errors, you are not impacted. If you see messages such as “Your connection is not private” or “certificate verify error”, your client does not trust one or more of the new CAs and you will need to update your configuration.
Timeline - The update will begin rolling out gradually starting March 15, 2026.
If your clients don’t trust all the Certificate Authorities listed above or are set to use only one, please update them to trust the root and intermediate certificates from all providers. This will help make sure your connections to Databricks continue to work without any interruptions.
Need help? If you have any questions about verifying or updating your client certificates, contact your Databricks account team or reach out to help@databricks.com.