How we ensure Cloudflare customers aren't affected by Let's Encrypt's certificate chain change
ID: 09c14cc8-6b0d-5d2a-93aa-aca226807d3a
STIX ID: report--09c14cc8-6b0d-5d2a-93aa-aca226807d3a
Feed Name: Cloudflare Blog
Cloudflare outlines how it will handle Let’s Encrypt’s shift away from the IdenTrust cross-signed chain (expiring September 30, 2024) by removing Let’s Encrypt as the default CA and proactively migrating Universal SSL and default SSL for SaaS certificates to other CAs to maintain compatibility for legacy clients (e.g., older Android versions). The post details Cloudflare’s resilient certificate pipeline—DCV automation, CAA handling, CA redundancy, short lifetimes/automation, and upcoming ECDSA support—along with a timeline (migration beginning June 2024, serving ISRG Root X1 for Let’s Encrypt from September 9, 2024) and guidance for customers who explicitly choose Let’s Encrypt or upload custom certificates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
