Let's Encrypt New Intermediate Certificates

I think it's very likely we start with 2 in use for each of RSA and ECDSA.

The "swapped in after 1 year" part is the most likely to change, as we learn from how the initial deployment goes.

It's possible we start with 3 or 4 in use immediately, holding 2 or 1 in reserve.

There's some variations on how we split issuance between the intermediates internally, but that shouldn't be visible externally.