Re: Plans for new ECDSA root and new intermediates from Let's Encrypt

2020-09-01 Thread Jacob Hoffman-Andrews via dev-security-policy
Update on this: Thanks to the excellent zmap/zlint tool, we realized we were missing the digitalSignature keyUsage on our planned new intermediates. We've updated the demo repo and our forum post ( https://community.letsencrypt.org/t/detailed-2020-hierarchy/131019) to indicate that we plan to

Plans for new ECDSA root and new intermediates from Let's Encrypt

2020-08-25 Thread Jacob Hoffman-Andrews via dev-security-policy
Let’s Encrypt is planning to issue a new root and new intermediates soon. The new root will be an ECDSA one, to augment our existing RSA root. The new intermediates will be part of our regular replacement of intermediates. Our RSA root will cross-sign the ECDSA root. We’re sharing our detailed