ACME v2: No "up" link in response

Yes. This behavior is explicitly documented in the ACME specification:

Yes, the second certificate will always be the intermediate that issued the first end-entity certificate.

But note that some CAs require longer certificate chains, and Let's Encrypt may do so in the future as well. So client software should not assume there will always only be two certificates in the chain.

3 Likes