Let's Encrypt New Intermediate Certificates

We considered having some intermediates only in a single DC, but while that works for issuance, we need to serve revocation (via OCSP and CRLs) from all DCs, so we need the intermediates online at all locations.

But externally, our CDN splits traffic randomly between DCs so it’s not geo-based or anything even if we do issue one intermediate from a single DC.

7 Likes