June 6, 2024 – DV SAN and Default DV trust chain changes

The cross-sign from IdenTrust’s DST Root CA X3 to the Let’s Encrypt ISRG Root X1 certificate will expire in September 2024. To prepare for this expiration, Let’s Encrypt has announced their plans to discontinue use of the cross-sign, and issue all certificates exclusively using their intermediate certificates signed by the ISRG Root X1 certificate. At the same time, Let’s Encrypt will be introducing new intermediate certificates for both ECDSA and RSA issuance.

These changes will affect:

  • All Default DV certificates provisioned in Property Manager
  • All DV SAN certificates provisioned in CPS
  • Akamai expects that most customers will notice no issues and will have to take no action when the DST Root CA X3 cross-sign expires, and when the new intermediates are introduced.

For full details, see the Community post DV SAN and Default DV trust chain changes in Q1 2024.