OS X 10.11 - Clients not connecting to site with Let's Encrypt certificates

You can't assume a "one size fits all" situation is possible. Some collateral damage is expected I'm afraid.

In my opinion, you can't expect a brand new CA to keep getting cross-signed intermediate certificates forever. This expiration of root certificates is not new: it's unfortunately part of the PKI infrastructure and some breakage is to be expected, especially in older, unsupported devices/software.

Also, Let's Encrypt is not the only CA out there. It's not even the only free CA out there. You have a choice :slight_smile: Notice that Let's Encrypt, being a CA which issues certificates free of charge, does not promise anything. Please see the Let's Encrypt Subscriber Agreement for your rights as a subscriber.

1 Like