Is Let’s Encrypt planning to switch to the “.well-known/pki-validation” directory in lieu of “.well-known/acme-validation”?
^^ Based on the above, it sounds like every CA is expected to implement a change to this directory, but I see nothing of this in the latest ACME draft.
If so, will this impact current issuance from Let’s Encrypt via the current production endpoint?
The implications of this ballot from back in August of last year have come up before (can't find a handy link now).
The new text introduced by Ballot 169 says:
Confirming the Applicant’s control over the requested FQDN by confirming one of the following under the “/.well-known/pki-validation” directory, or another path registered with IANA for the purpose of Domain Validation, on the Authorization Domain Name that is accessible by the CA via HTTP/HTTPS over an Authorized Port:
The key part is or another path registered with IANA for the purpose of Domain Validation.