# Sign domain certificate like an intermediate certificate authorities

**URL:** <https://community.letsencrypt.org/t/sign-domain-certificate-like-an-intermediate-certificate-authorities/173535>\
**Category:** Feature Requests\
**Created:** [March 10, 2022, 4:56am UTC](https://community.letsencrypt.org/t/sign-domain-certificate-like-an-intermediate-certificate-authorities/173535 "2022-03-10T04:56:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kyungmin.kim](https://avatars.discourse-cdn.com/v4/letter/k/f0a364/32.png) [@kyungmin.kim](https://community.letsencrypt.org/u/kyungmin.kim)\
**Post date:** [March 10, 2022, 4:56am UTC](https://community.letsencrypt.org/t/sign-domain-certificate-like-an-intermediate-certificate-authorities/173535/1 "2022-03-10T04:56:39Z")

</div>

Hello,

Can I use letsencrypt client to sign my domain certificate like an intermediate certificate authority?  
(to sign [www.mydomain.com](http://www.mydomain.com) using r3 certificate.)

ISRG Root X1 \> R3 \> [community.letsencrypt.org](http://community.letsencrypt.org)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 10, 2022, 5:43am UTC](https://community.letsencrypt.org/t/sign-domain-certificate-like-an-intermediate-certificate-authorities/173535/2 "2022-03-10T05:43:26Z")

</div>

No.  
Only **`server authentication`** and **`client authentication`**"roles" are supported.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 10, 2022, 7:14am UTC](https://community.letsencrypt.org/t/sign-domain-certificate-like-an-intermediate-certificate-authorities/173535/3 "2022-03-10T07:14:57Z")

</div>

Let's Encrypt does not offer subsidiary CAs from their chain of trust.

Also, the intermediate certificates used have the `pathlen` set to 0:

```nohighlight
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0

```

(Source: [Chain of Trust - Let's Encrypt](https://letsencrypt.org/certificates/))

That means that any certificate signed by R3 or E1 can **never** be a certificate with "CA:TRUE", so any cert issued by R3 or E1 can _not_ be used to sign other certificates.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 9, 2022, 7:15am UTC](https://community.letsencrypt.org/t/sign-domain-certificate-like-an-intermediate-certificate-authorities/173535/4 "2022-04-09T07:15:14Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
