# Does Let's Encrypt offer intermediate certificates?

**URL:** <https://community.letsencrypt.org/t/does-lets-encrypt-offer-intermediate-certificates/71957>\
**Category:** Issuance Policy\
**Created:** [September 11, 2018, 3:40pm UTC](https://community.letsencrypt.org/t/does-lets-encrypt-offer-intermediate-certificates/71957 "2018-09-11T15:40:48Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [September 11, 2018, 6:03pm UTC](https://community.letsencrypt.org/t/does-lets-encrypt-offer-intermediate-certificates/71957/4 "2018-09-11T18:03:30Z")

</div>

I wonder if there's an easier path with a name-constrained intermediate; I don't know how that affects the auditing requirements. I thought that there was once an option involving name constraints that was much less rigorous in some regard, but I don't know if that still exists.

> **[pki nameconstraint at DuckDuckGo](https://duckduckgo.com/?q=pki%2Bnameconstraint)**
>
> DuckDuckGo. Privacy, Simplified.

Anyway, maybe you could ask a commercial CA and/or PKI consultant about this option. Ideally it would lead to less stringent audit requirements than an unconstrained public CA. (Individual X.509 extensions can be marked as Critical which means that a client that doesn't understand the semantics of the extension should reject the certificate, whereas for a Not Critical extension a client that doesn't understand the extension may still accept the certificate. So the name constraint is normally always set as a Critical extension so that software that doesn't understand the restriction simply can't use those certificates at all... but I think all recent browsers do understand it.)

... actually, we have a forum thread from 2016 about this topic

> [@Sign me as an Intermediate CA for my Domain with Name Constraint?](https://community.letsencrypt.org/t/sign-me-as-an-intermediate-ca-for-my-domain-with-name-constraint/17140):
>
> W…

which says that at least at that time, Comodo offered this service commercially.

---

_[View the full topic](https://community.letsencrypt.org/t/does-lets-encrypt-offer-intermediate-certificates/71957)._
