Questions regarding "Shortening the Let's Encrypt Chain of Trust"

Correct

Well, eventually it will need to change to something else, since eventually ISRG Root X1 will even be expired, but it probably won't need to change for quite some time. If selecting a specific chain, though, I'd recommend watching the API Announcement category in order to make sure one knows when and if to change it.

No, one of many, many things where the ACME protocol doesn't actually expose the things to the client that the client needs to know about. In theory, each certificate issued by an ACME server can be from a different chain. (Which is kind of what happens now with the ECDSA allowlist.)

5 Likes