"EC XXX bits (SHAXXXwithRSA)" versus "EC XXX bits (SHAXXXwithECDSA)"? What's the difference? Does it matter?

Even if one served the leaf←E1←RootX2←RootX1←DST chain (and again, serving a chain that long means you're losing some of the benefit of ECDSA), Android 7.0 still can't validate E1's P-384 signature, so you'd lose those clients.

But if all your Android users are new enough, then pretty much anything else that a person would use for web browsing supports ECDSA and ECDSA signatures just fine.

8 Likes