( gemnon | 2024. 04. 05., p – 13:44 )

The transition will roll out as follows:

  • On Thursday, Feb 8th, 2024, we stopped providing the cross-sign by default in requests made to our /acme/certificate API endpoint. For most Subscribers, this means that your ACME client will configure a chain which terminates at ISRG Root X1, and your webserver will begin providing this shorter chain in all TLS handshakes. The longer chain, terminating at the soon-to-expire cross-sign, will still be available as an alternate chain which you can configure your client to request.

https://letsencrypt.org/2023/07/10/cross-sign-expiration.html

De legalább az "informatikaibiztonságiprüttypürütty" végre boldog lesz, hogy végre nem hozza közepes sebezhetőségnek a Nessus. :)

https://community.tenable.com/s/article/Resolving-results-for-plugin-51…