Questions re: Beginning Issuance from R3

What was your plan when X3 expired in 2021, or if they needed to bring the disaster recovery intermediate X4 online?

If your servers followed the best practice of renewing every 60 days, you should still have your older server certificate somewhere that was signed by X3 that should expire at some point in the next month. If you can restore that certificate and use it for your server, you should have a small window until it actually expires. I recommend you update your devices to chain to the ISRG root (and also include some other CAs rather than relying on Let's Encrypt being around forever) instead of a specific intermediate. Intermediates can change at any time.

You may also want to check out this thread by someone else who was looking at what to put in the trust store of their IoT devices, which has some additional ideas and cautions:

6 Likes