# Production Chain Changes

**URL:** <https://community.letsencrypt.org/t/production-chain-changes/150739>\
**Category:** API Announcements\
**Created:** [April 29, 2021, 5:05pm UTC](https://community.letsencrypt.org/t/production-chain-changes/150739 "2021-04-29T17:05:40Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![jillian](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jillian/32/11635_2.png) [@jillian](https://community.letsencrypt.org/u/jillian)\
**Post date:** [September 29, 2021, 1:11am UTC](https://community.letsencrypt.org/t/production-chain-changes/150739/4 "2021-09-29T01:11:33Z")

</div>

> [@jillian](#):
>
> **After September 29, 2021**
> 
> Our default chain and alternate chain will not change, but DST Root CA X3 will expire. Android devices as far back as 2.3.6 will continue to work. Non-Android devices that aren't getting system updates will show certificate errors. On some platforms, using Firefox will be a workaround, since Firefox gets updates even on many out-of-date OSes.
> 
> We will periodically issue new intermediates to replace E1, E2, R3, and R4. These intermediates will be signed by ISRG Root X1 or ISRG Root X2, as appropriate to their key type.

Hello again! Since the DST Root CA X3 expires at Sep 30 14:01:15 2021 GMT, here’s an update that may be helpful to you!

We have a [page on our website that talks specifically about this expiration](https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/).

If you are using OpenSSL 1.0.2, [there are several workarounds available](https://www.openssl.org/blog/blog/2021/09/13/LetsEncryptRootCertExpire/).

If you are using very old versions of Firefox (prior to version 50, in November 2016) that no longer can receive updates of their root store, please upgrade to a newer version of Firefox.

Windows users may have some unique issues - [please check out this write-up](https://docs.certifytheweb.com/docs/kb/kb-202109-letsencrypt/) from @webprofusion.

Two weeks ago we spoke with Boulder developer Aaron Gable about this expiration in detail - [check out the video here](https://www.youtube.com/watch?v=RIR-_V1fNrk).

[Here’s where you can find more information](https://letsencrypt.org/certificates/%E2%80%A8) about the Let’s Encrypt Certificate Hierarchy.

We have [extended Android device compatibility for Let’s Encrypt certificates](https://letsencrypt.org/2020/12/21/extending-android-compatibility.html) through use of a cross-sign.

Andrew Ayer did [a great write-up of fixing the breakage](https://www.agwa.name/blog/post/fixing_the_addtrust_root_expiration) from the AddTrust External CA Root expiration in May 2020.

For all changes with our API, [we post in the API Announcements category in our community forum](https://community.letsencrypt.org/c/api-announcements/18). Sign in and hit the bell for notifications to be sent to your email!

We (and our community) are here for you! If you have any questions about this change, search on our community forum or [post on the thread we have to help you with this very topic](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190).

---

_[View the full topic](https://community.letsencrypt.org/t/production-chain-changes/150739)._
