4 ms·
This is because the IdenTrust root is expiring though, it's not something LetsEncrypt can do anything about.
by pcnix 7y ago
This is because the IdenTrust root is expiring though, it's not something LetsEncrypt can do anything about.
- profmonocle 7y agoThey could get a new cross-signed intermediate from a root with broader compatibility. Though I imagine that's extremely expensive. I expect that has something to do with this decision - they are a non-profit after all.
- panarky 7y ago> it's not something LetsEncrypt can do anything about This is going to cause a lot of stuff to break, and it's 100% LE's responsibility. HN's root cert is valid through 2038. LE could have gotten cross-signed by a cert that didn't expire so soon, but they didn't.
- londons_explore 7y ago> LE could have gotten cross-signed by a cert that didn't expire so soon, but they didn't. And they still could.