Possible Issues on Windows with new YE/YR hierarchy

Note the default chain provided by LE includes the cross-signs to X2 and X1

But, yes, if someone chose a shorter alternate chain they need to ensure all TLS clients' trust stores include at least one of the included roots.

I submitted a Feature Request to have the alternate Gen Y chains documented: Update Certificates Chains section for Gen Y Hierarchy

You can discover the chains by reviewing the ACME Client's API results. I mention this for others as I know you know how to do that @webprofusion :slight_smile: Personally I would avoid relying on specific alternate chains until they are documented.

4 Likes