New Quad9 SSL Certificate - Mikrotik Devices Must Import New Root Certificate!
Incident Report for Quad9 Public Network Status Page
Resolved
This incident has been resolved.
Posted Jul 25, 2024 - 16:39 UTC
Investigating
Quad9 deployed a certificate which uses a new Root SSL certificate from DigiCert.

MikroTik devices will need to download and import a new certificate manually if Certificate Validation is enabled. Devices which do not have the new certificate, and have Certificate Validation enabled, will stop being able to resolve DNS.

The new certificate should be able to be imported via the following CLI commands in Mikrotik:

/tool/fetch mode=https url="https://cacerts.digicert.com/DigiCertGlobalG3TLSECCSHA3842020CA1-1.crt.pem"
/certificate/import file-name=DigiCertGlobalG3TLSECCSHA3842020CA1-1.crt.pem

We apologize for the inconvenience.

Please reach out to us with any questions or concerns:
support@quad9.net
Posted Jul 25, 2024 - 16:21 UTC
This incident affected: Recursive DNS Services (Current Status).