The cross-sign from IdenTrust’s DST Root CA X3 to the Let’s Encrypt ISRG Root X1 certificate will expire in September 2024. To prepare for this expiration, Let’s Encrypt has announced their plans to discontinue use of the cross-sign, and issue all certificates exclusively using their intermediate certificates signed by the ISRG Root X1 certificate.
This change will affect:
- All Default DV certificates
- All DV SAN certificates with no trust chain selection (the default option)
- All DV SAN certificates with the “R3 + ISRG Root X1 (signed by DST Root CA X3)” chain selected
Akamai expects that most customers will notice no issues when the DST Root CA X3 cross-sign expires, and most customers will have to take no action.
For full details, please see the Community post DV SAN and Default DV trust chain changes in Q1 2024.