Policy on Issuance Chain Changes

I guess this depends a bit on how close you were following the development. The ECDSA chain was always intended to be the only issuer for ECDSA leafs. It was just hidden behind an allowlist for the past 3 years, but it was clear that this change would come eventually, ever since the ECDSA chain became a thing in 2021.

When the new certificates were announced in March 2024, it was hinted that the ECDSA allow list would (finally) go away soon (and hence result in every ECDSA leaf being signed with an ECDSA intermediate):

This reduces the size of our default ECDSA chain by about a third, and is an important step towards removing our ECDSA allow-list.

The final decision to abolish the allowlist was indeed only announced on April 12th. So I guess this was implicitly clear to inside folks, but perhaps not clearly communicated to the public.

Which client supports an ECDSA leaf certificate, but does not support an ECDSA intermediate? Could you name an example? Compatibility issues like this are - I believe - not expected.

Let's Encrypt has previously held the stance that intermediates can change at any time, for any reason. Let's Encrypt has always had backup certificates that could have been activated at any time, without any prior notice. Admittedly, this generally doesn't involve a change of cryptographic algorithms - but with future cryptographic agility in mind, this may become a more common reality.

12 Likes