A fix has been implemented and we are monitoring the results.
Posted May 30, 2020 - 18:22 UTC
The TLS certificate we are using is based upon a cross-signed root certificate issued by Comodo. One of the trust pathways expired at around 7:00AM Eastern Time today. The expired trust pathway has been mitigated in modern and updated software systems including web browsers and operating systems. A handful of clients using older (often unmaintained or unsupported) operating systems and versions including RedHat Linux 4.x or old versions of libcurl and OpenSSL) have been experiencing connectivity issues because updates to root certificates were not available on these older systems.
As a mitigating effort, we identified a third possible trust pathway that many of these older clients might be able to utilize with our cross-signed certificate and we added the appropriate intermediate certificates in the chain in order to allow that alternate pathway to be utilized so long as the additional certificate authority (AAA Certificate Services, expiration 2028) is trusted by the system.
We are investigating reports of users receiving TLS certificate validity errors.
Posted May 30, 2020 - 16:35 UTC
This incident affected: US Autocomplete API, US Autocomplete Pro API, International Street API (us-east, us-central, us-west), US Extract API (us-east, us-central, us-west), US ZIP Code API (us-east, us-central, us-west), and US Street Address API (us-east, us-central, us-west).