R3 still issuing certificates

I'm confused.

According to the root certificates page (Chains of Trust - Let's Encrypt) , "Let's Encrypt R3" is listed under the section entitled "Retired: These intermediate CAs are no longer being used to issue Subscriber certificates."

However my Let's Encrypt client (LEGO) appears to be happily issuing new certs signed by R3 ?

Welcome to the Let's Encrypt Community! :slightly_smiling_face:

The changeover from R3 doesn't happen until June, I think.

5 Likes

@griffin's correct, the page mentions two sections: one after 6th of June (top) and one before the 6th of June (bottom).

See the "Note: …" above both sections.

4 Likes

I see, thanks @griffin . A bit premature posting the content early, no ? :wink:

2 Likes

No.

The sections are clearly marked with a note. Posting both chains, before and after, ahead of the change only helps people with the change.

3 Likes

I concur with @Osiris.

:thinking: Plan all
:magic_wand: Execute automagically

4 Likes

I mean, I think they could have phrased things a little clearer, having all the intermediates together rather than one section up top only talking about the after-June-6 configuration, and then basically another whole page just sitting below it for the existing chains. But they wanted to just be able to delete the bottom part once they deploy the change, which I can understand.

6 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.