Discovering/Identifying Roots

Agree with @kjb the intermediate certificate in the default chain has AIA CA Issuers that yields a certificate with Subject not same as Issuer in the intermediate certificate.

Also the alternate chain when downloaded has 1 EE/Leaf certificate and 1 intermediate - the entire chain looks to have four certificates EE->stg-r3.i.lencr.org->stg-x1.i.lencr.org->stg-dst3.i.lencr.org. I was under the impression (from this thread: Questions re: OpenSSL Client Compatibility Changes for Let’s Encrypt Certificates - #4 by joeshaw) that the long chain would provide the EE certificate and the multiple intermediate certificates. Is my impression mistaken, or should the alternate chain download provide 3 certificates in this case?

Thanks!!

1 Like