New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Preferred chain: LetsEncrypt Subscriber Certificate < – R3 < – ISRG Root X1 #808
Comments
|
This is already supported in the newest version. Either as CLI argument:
Or via a config parameter: |
|
So, the question arose due to this note from LetsEncrypt: Specifically, the note about "no acme clients having a way to select this alternate chain...". If the existing preferred-chain option in dehydrated doesn't suffer this issue, that's great. |
|
My current implementation just travels up the trust chain until it gets to the uppermost issuer certificate, which in this case should be
|
it seems that is the case, cos i checked my cert at the browsers and still shows R3 as issuer.. check #892 or i dont know how is the workflow of those mechanish?
|
As relates to https://letsencrypt.org/2020/12/21/extending-android-compatibility.html, it sounds like there is presently no way to select the alternate chain LE is going to offer (Subscriber Certificate < – R3 < – ISRG Root X1). Is this something that's in the works?
The text was updated successfully, but these errors were encountered: