Skip to content

Conversation

@aarongable
Copy link
Contributor

The chains documentation had gotten out of date because it is down at the bottom of the doc where its easy to miss. Move the listing of the actual chains we offer inline with the active intermediates. Update the prose documentation at the bottom of the article to be more future-proof.

@aarongable aarongable marked this pull request as ready for review January 8, 2026 23:25
@aarongable aarongable requested a review from mcpherrinm January 8, 2026 23:26
Copy link
Contributor

@mcpherrinm mcpherrinm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, though I have one suggestion that I think might look a bit nicer.

@aarongable
Copy link
Contributor Author

Tidied up how defaults are indicated and fixed a couple mistakes I found at the same time.

@aarongable aarongable requested a review from mcpherrinm January 9, 2026 00:06
@aarongable aarongable merged commit c2037f6 into main Jan 9, 2026
5 checks passed
@aarongable aarongable deleted the gen-y-chains branch January 9, 2026 04:43
Sometimes there's more than one valid chain for a given certificate: for example, if an intermediate has been cross-signed, then either one of those two certificates could be the second entry, "chaining up to" either of two different roots. In this case, different website operators may want to select different chains depending on the properties that they care about the most.

Subscriber certificates with RSA public keys are issued from our RSA intermediates, which are issued only from our RSA root ISRG Root X1 (i.e. they are not cross-signed). Therefore, all RSA subscriber certificates have only a single chain available:
Each of the active intermediates above documents which chain is offered by default, and which (if any) additional chains may be requested by ACME clients. In general, chains which terminate at ISRG Root X1 have the largest size but also the greatest compatibility with older clients. Chains which terminate at ISRG Root X2 (only offered for ECDSA certificates) are smaller, but will only work with clients that have received an update to their trust store after 2022 or so. Chains which terminate at Root YE or Root YR will are not expected to work with any of the major trust stores, as those roots have not yet been incorporated.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"will are not expected to work" (double auxiliary verb).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants