# Shortening the Let's Encrypt Chain of Trust

**URL:** <https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580>\
**Category:** API Announcements\
**Created:** [July 10, 2023, 7:11pm UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580 "2023-07-10T19:11:25Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)\
**Post date:** [July 10, 2023, 7:11pm UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/1 "2023-07-10T19:11:25Z")

</div>

We have [just published a blog post](https://letsencrypt.org/2023/07/10/cross-sign-expiration.html) detailing our plans to handle the expiration of our ISRG Root X1 cross-sign from IdenTrust’s DST Root CA X3.

The summary is:

- On **2024-02-08** , we will stop providing the long chain by default, but clients can still be configured to request it.
- On **2024-06-06** , we will stop providing the long chain at all.
- On **2024-09-30** , the cross-sign will expire, and any websites still serving it in their TLS handshakes may run into difficulties.

No action on your part is needed. You have the option of doing some manual configuration of your ACME client to gain six extra months of compatibility for older Android devices visiting your sites. If you have any questions, please direct them to [this thread](https://community.letsencrypt.org/t/questions-regarding-shortening-the-lets-encrypt-chain-of-trust/201581).

---

<div class="post-metadata">

**Author:** ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)\
**Post date:** [November 13, 2023, 9:05pm UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/2 "2023-11-13T21:05:47Z")

</div>

Some of you [may](https://community.letsencrypt.org/t/no-more-isrg-root-x1-in-my-pem/208252) [have](https://community.letsencrypt.org/t/production-environment-we-are-getting-exception-when-processing-orders/208263) [noticed](https://community.letsencrypt.org/t/can-not-find-issuer-c-us-o-internet-security-research-group-cn-isrg-root-x1-for-certificate-c-us-o-lets-encrypt-cn-r3/208268) that, from Thursday, Nov 9, 17:30 UTC to Monday, Nov 13, 20:45 UTC, we were providing the short chain by default for certificates issued from R3. This was an accidental misconfiguration, and has been reverted.

However, the change observed over the past few days is identical to the change that we will be making on February 8, as announced above. If this change caused issues for your client, please prepare now for the upcoming changes. The blog post linked above has details on how.

---

<div class="post-metadata">

**Author:** ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)\
**Post date:** [January 16, 2024, 9:07pm UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/3 "2024-01-16T21:07:46Z")

</div>

Reminder that the short chain will become the default, and the compatibility chain will be moved to be an alternate, in **approximately three weeks**. See the above announcements for details.

---

<div class="post-metadata">

**Author:** ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)\
**Post date:** [January 30, 2024, 7:58pm UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/4 "2024-01-30T19:58:51Z")

</div>

Reminder that the short chain is scheduled to become the default on **Feb 8** , just over **one week** from now.

---

<div class="post-metadata">

**Author:** ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)\
**Post date:** [February 6, 2024, 12:44am UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/5 "2024-02-06T00:44:58Z")

</div>

Reminder: on Thursday of this week, the /acme/certificates API endpoint will begin serving the short chain (rooted at our own self-signed ISRG Root X1) by default, and only offering the long chain (rooted at DST Root CA X3) as an alternate. If your ACME client is configured to simply download and install the default chain provided by our API, then your visitors will begin seeing the short chain the next time your certificate is renewed.

---

<div class="post-metadata">

**Author:** ![JamesLE](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jamesle/32/49364_2.png) [@JamesLE](https://community.letsencrypt.org/u/JamesLE)\
**Post date:** [February 8, 2024, 12:30am UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/6 "2024-02-08T00:30:38Z")

</div>

The **staging** environment is now serving its short chain by default.

---

<div class="post-metadata">

**Author:** ![JamesLE](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jamesle/32/49364_2.png) [@JamesLE](https://community.letsencrypt.org/u/JamesLE)\
**Post date:** [February 8, 2024, 7:31pm UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/7 "2024-02-08T19:31:23Z")

</div>

The **production** environment is now serving its short chain by default. If you have any questions, please direct them to [this thread](https://community.letsencrypt.org/t/questions-regarding-shortening-the-lets-encrypt-chain-of-trust/201581).

---

<div class="post-metadata">

**Author:** ![mcpherrinm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mcpherrinm/32/59604_2.png) [@mcpherrinm](https://community.letsencrypt.org/u/mcpherrinm)\
**Post date:** [June 7, 2024, 3:20am UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/8 "2024-06-07T03:20:28Z")

</div>

> [@aarongable](#):
>
> On **2024-06-06** , we will stop providing the long chain at all

This change went live today. The cross-sign from IdenTrust’s DST Root CA X3 is no longer provided in our API.

---

<div class="post-metadata">

**Author:** ![mcpherrinm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mcpherrinm/32/59604_2.png) [@mcpherrinm](https://community.letsencrypt.org/u/mcpherrinm)\
**Post date:** [September 23, 2024, 5:26pm UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/9 "2024-09-23T17:26:02Z")

</div>

The cross-sign of ISRG Root X1 from IdenTrust's DST Root CA X3 expires on **2024-09-30** , one week from today.

---

<div class="post-metadata">

**Author:** ![mcpherrinm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mcpherrinm/32/59604_2.png) [@mcpherrinm](https://community.letsencrypt.org/u/mcpherrinm)\
**Post date:** [September 30, 2024, 6:46pm UTC](https://community.letsencrypt.org/t/shortening-the-lets-encrypt-chain-of-trust/201580/10 "2024-09-30T18:46:16Z")

</div>

The cross-sign of ISRG Root X1 by DST Root CA X3 has now expired.
