I can't get the ISRG Root X2 certificate now

I can't get the ISRG Root X2 certificate now,My account has been able to obtain the ISRG Root X2 certificate before, but now I only get the X1 certificate when I renew the certificate. Why can't I get the X2 certificate?

The ISRG Root X2 certificate is downloadable from the Chain of Trust page. But I don't think that's what you meant.

It sounds like you were getting previous certificates signed by the ECDSA intermediate, E1, which was signed by ISRG Root X2? And now your new certificates are being signed by the RSA intermediate, R3, which was signed by ISRG Root X1?

If so, can you provide the domain name in one of the certs so folks here can verify the issuance history? Did anything else change on the server that might have caused a change in the ACME client configuration?


yes. the domain xiaoyu.net was signed by ISRG Root X2. i don't know why it is X1 now.

You probably changed the account used to request the cert. Review this topic for instructions


I did not change account.

i try apply allow list again, get this reply email:

Your request for your ACME account ID to be placed on the Let's Encrypt ECDSA allowlist has been moved to production. Now when you request a cert from Let's Encrypt with your ECDSA key, the cert will be issued from our ECDSA hierarchy.

If you have any further questions or feedback about how ECDSA certificates are working in your environment, please post on our helpful Community Forums: https://community.letsencrypt.org/

so if you get another cert do you get it with the X2? Also, you should review your SSL labs report because your IPV6 looks wrong


Did something change on your server around April 1? CT Logs show you got both an E1 and R3 issued cert on that date. The E1 one was issued a bit over an hour after the R3 one.


I first failed to apply for a certificate using the acme of pfsense. I had to use the Certify software to apply for a certificate successfully with the same account, but it was an R3 certificate.

now pfsense acme show has E1 cert.

