I used 2 1 1 with the IdenTrust root. The main disadvantage of this, I think, is that you have to send the root in your certificate chain, which is unusual, but shouldn’t cause any problems.
hlandau
5
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| DANE and upcoming LE issuer certs | 17 | 6236 | October 26, 2020 | |
| TLSA record hygiene for Let's Encrypt issuer CAs | 16 | 618 | June 17, 2025 | |
| Understanding SMTP DANE implementation options | 12 | 6582 | September 14, 2022 | |
| A DANE-friendly Certbot workflow | 3 | 2350 | August 24, 2021 | |
| TLSA record changes with every renewal process which breaks DANE | 8 | 6232 | January 31, 2021 |