Certbot issues ECDSA key signed with RSA

You've haven't read the entire announcement:

You only mention one line [which is correct] and have taken it out of context.
The context for it is in the preceding sentences:

  • With a production allow-listed account
    [something you don't yet have & certbot 2.1.0 doesn't provide]
    [certbot 2.1.0 only defaults to ECDSA leaf - no longer RSA leaf]

Until then, you (and the rest of us) will receive what production provides:

  • RSA signed RSA leaf
  • RSA signed ECDSA leaf

Unless you are using a testing/staging cert:

[note: production and staging accounts are separate - not interchangeable]

5 Likes