Ready to test shortest ECDSA only ISRG Root X2

Reinstalled acme.sh and ready to test the new short chain on a fresh new account. I will test in a couple of hours.

3 Likes

Keep in mind the chain service changes that will be happening today.

2 Likes

Yes, like I said I will be testing the shortest X2 chain without being on the allow list. I deleted the account folder and requesting a new shortest chain certificate using acme.sh --issue ... --preferred-chain "ISRG Root X2" --keylength ec-256

3 Likes

Sweet, let us know how it goes! We'll be posting in the announcement thread as soon as the new intermediates and chains are live.

3 Likes

Is it ready to request from X2 only chain?

Have you seen an announcement thread yet? No? Then it's not yet ready.

Well, it was just announced, and it looks like E5 is issuing now (and E6 too, of course).

5 Likes

:tada: :tada: :tada: ‎‎‎‎‎‎

3 Likes

Crap, I should have made a for loop issuing certs until one came back with E5 or E6 as issuer so I could have said "FIRST!" :joy:

Anyway, no announcement yet, but surely it'll come soon :slight_smile:

3 Likes

Looks like I have X2 - E5 - leaf certificate.

7 Likes

Our Root X2 test websites (e.g. valid-isrgrootx2.letsencrypt.org) are also now serving the EE <- E5/6 <- X2 chain.

4 Likes

Congrats. 50 % chance! (Probably.)

1 Like

Have you stopped using the IRSG Domain Validated OID (1.3.6.1.4.1.44947.1.1.1) in the Certificate Policies extension for the intermediate certs? This used to be set on the R3 intermediate. In a previous discussion I understood that this certificate policy would not be set on the requested certificates, but it would always be set on at least one CA in the chain.

2 Likes

This was announced back in Dec 2023 that the new intermediates would not contain additional policy OIDs (Let's Encrypt New Intermediate Certificates).

6 Likes

Everything is working fine now, got the shortest ECDSA chain from X2.

Thanks for everything.

6 Likes

OK, thanks, I must have missed that one.

5 Likes

It is crt.sh | saudiqbal.com

3 Likes

Forgot to mention that thanks for supporting IPv6 only DNS servers for validating dns-01 challenge.

4 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.