Let's Encrypt New Intermediate Certificates

Perhaps, but I thought that this issue was one of the main reasons people might not want all their ECDSA certs signed by a P-384 ECDSA chain, which is why the current system might still be opt-in-only for now (though I may just be wildly speculating). Some people might want an ECDSA chain that only uses P-256 signatures, which they can get from other CAs (I think) but not with the Let's Encrypt current (or these proposed) intermediates.

5 Likes