So now that R3 is live in production (hooray!), I still don't see any changes in staging. (Or at least, a staging certificate that I just issued and one I tried a couple weeks ago are both signed by the same "Fake LE Intermediate X1".) Is there still a change expected in staging relating to this change?
My guess is that (one of the things) they're working on before bringing the new intermediates into service is updating the CPS . Section 7.1 only mentions the
X<n>
certificates, so I'm guessing they need to add at least theR<n>
certificates there before they can be used. So keep your eyes peeled there if you want another hint of when they're about to use the new intermediates.
This guess of mine was apparently wrong, as the CPS section 7.1 still says that the CN of intermediates will be Let's Encrypt Authority X<n>
. Is this a problem, or is that part of the CPS not actually authoritative but just describing the initial intermediates and not necessarily all active intermediates?