Thank you for the response & shared links @MikeMcQ
I do understand the criticality of it and with no doubt it was a major critical lack by our team to pin R13 instead of recommended root cert.
We have already corrected this mistake & rigorously tested our new device firmware to use recommended ISRG Root X1 cert.
Further to push update to all devices, devices need to be able to connect to server, but since current cert has expired, they're failing to connect. We had been exploring different ways, but there seems no other way to get them online even once to receive update.
Referring to shared post: Is there any way to resume R11 in Let's Encrypt - Help - Let's Encrypt Community Support. Yes, the issue is similar but not exactly same as in previous case R11 had expired, but in current case R13 is valid till 2027-03-12.
Moreover, from this post: Upcoming Let’s Encrypt Profile Changes On May 13, 20th, and 27th, came to know that switch to Y-generation intermediaries was done only few weeks back, I believe as part of LE intermediates rotation.
Also, since we used default ‘classic’ profile last time, we’re unable to use ‘tlsclient’ profile to get R13 intermediate signed cert.
I understand LE team has limited resources and functions with small team, as we too are a small team of start-up with few engineers and this is proving to be costly mistake & big learning. Pardon me for this as we’re not much experienced with SSL & encryption, etc. and had no idea such thing would happen.
I would be highly grateful if LE staff or anyone would help us.