Why do Letsencrypt still add the expired root cert?

From the certbot documentation for --preferred-chain:

prefer the chain whose topmost certificate was issued from this Subject Common Name.

From Providing a longer certificate chain by default also linked above:

This chain will consist of three certificates, instead of the current two:

  • End-entity certificate (aka leaf certificate), signed by R3
  • R3, signed by ISRG Root X1
  • ISRG Root X1, signed by DST Root CA X3

Our API will also offer an "alternate" chain, which you may configure your ACME client to select instead:

  • End-entity certificate, signed by R3
  • R3, signed by ISRG Root X1

The possible values for the --preferred-chain clearly indicated by the "signed by" followed by the required common name.

Although perhaps some explanation about what a Common Name actually is might be helpful, it's not rocket science.

3 Likes