2 ms·
This solution wasn't perfect. Although things were mostly resolved pretty quick, it led to one of the longest threads I've ever seen on the LE forums: https://c
by profmonocle 3y ago
This solution wasn't perfect. Although things were mostly resolved pretty quick, it led to one of the longest threads I've ever seen on the LE forums: https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190 https://community.letsencrypt.org/t/help-thread-for-dst-root...
IIRC one of the bigger problems was that older versions of OpenSSL did check root anchor expiration. But that wasn't all - at my then-employer we had a brief outage on some of our systems because Ubuntu had to patch something (I don't recall what) to deal with this, and they only released the patch a few days before the expiration. We had to mass-rebuild all our Docker images to fix the issue.
This workaround was so wild and unprecedented that I assume the cost difference vs. getting cross-sig from an unexpired (and widely compatible) root was massive for them to use it. There must have been a huge amount of testing involved. The fact that it went as smoothly as it did (mostly, but not completely) was impressive.