What is the chain to pass to --preferred-chain argument to keep using DST Root X3 root certificate?

For the purposes of testing --staging --preferred-chain "Fake LE Root X2" will work, even if it's in cli.ini.

I posted the names of the chains earlier here.

The Certbot team had planned to make an announcement on how to prepare for the transition if you plan to use the legacy chain. That's what I linked 2 posts ago. I think it was supposed to come out at the same time as the Let's Encrypt post. Obviously that didn't happen and we're getting lots of posts about it now.

Ultimately you have to put some trust into the instructions it provides (when posted) because 50% of this change is on the CA side, so there is no perfect reproductive test.

3 Likes