Let’s Encrypt Halts Certificate Issuance for Two Hours After Root Certificate Issue

Last updated: May 11, 2026 Reading time: 4 minutes
Disclosure
Share
Let’s Encrypt Halts Certificate Issuance for Two Hours After Root Certificate Issue
  • Let’s Encrypt halted all certificate issuance for about two and a half hours on May 8 – this was after discovering a cross-signed root certificate problem affecting its Generation Y root transition.
  • The organization rolled back two certificate profiles (tlsserver and shortlived) to the Generation X root following the incident, which occurred just five days before major planned platform changes.
  • Three scheduled updates, including 45-day certificates, remain on track for May 13, pending full resolution of the root certificate issue, though Let’s Encrypt has not disclosed whether any incorrect certificates were issued.

Let’s Encrypt temporarily stopped issuing digital certificates on May 8, 2026, after engineers discovered a serious problem involving a cross-signed root certificate. The organization suspended all issuance across both its production and testing systems before restoring services later that same day.

The incident began at 18:37 UTC when company engineers identified a potential security issue. They immediately halted all certificate generation as a safety measure. The impacted systems were the production and staging ACME API endpoints, as well as two high-assurance data center portals.

Let’s Encrypt confirmed that certificate services returned to normal operation at approximately 21:03 UTC, approximately 2 and a half hours after the initial shutdown. In addition, Let’s Encrypt has rolled back all certificate generations to Generation X Root because of a cross-signature certificate issue.

Generation Y Root Transition Hit Technical Snag Just Days Before Planned Launch

This incident purportedly has some major implications associated with its timing. Let’s Encrypt has already announced the following three significant platform changes to occur on May 13, 2026, just five days before the related project shutdown.

One planned change relates to the tlsserver ACME profile. It proposes the issuance of 45-day certificates as part of Let’s Encrypt long term goal to cut down the present 90-day to 45-day certificate lifetimes over the next two years.

Another update affects the TLS client profile, which is used for authenticating TLS client certificates. The organization will restrict this profile completely to ACME accounts that have issued past request of certificates from the service. Full support for TLS client certificates will end on July 8, 2026.

The typical ACME profile also faced a scheduled transition to the Generation Y intermediates. These new intermediates will now link to the current X1 and X2 roots and are necessary for continued interoperability across client environments whenever they are implemented.

All three intended changes were in a running state on Let’s Encrypt’s staging environment at the time of the incident. The company stated that this incident will not impact the deployment of the planned production rollout on May 13, while they work on resolving the root certificate issue

Two Certificate Profiles Remain Rolled Back to Generation X Root

The root certificate problem directly impacts two specific profiles of ACME certificates. The short-lived and TLS server profiles now fall under the Generation X root following the rollback.

Let’s Encrypt has not disclosed whether any incorrectly issued certificates reached users before the organization halted issuance. The company remains tight-lipped about the exact nature of the cross-signed certificate issue that triggered the shutdown.

The Generation X root represents older infrastructure for the certificate authority. The Generation Y root, previously scheduled for activation, would have offered updated security features and improved compatibility with modern systems.

Administrators who rely on automated ACME-related renewal workflows should pay close attention to their systems. Those using the short-lived or TLS server profiles need to monitor renewal logs carefully. They should verify that any certificates issued around the May 8 window chain correctly to the expected root certificate.

Let’s Encrypt continues to provide updates and community support through its official community forum. Also, the organization asks users to report any certificate anomalies they detect following the incident.

Certificate Authority Faces Scrutiny After Rare Service Disruption

Let’s Encrypt operates as one of the world’s largest certificate authorities, providing free SSL/TLS certificates to millions of websites. The organization has earned widespread trust for its automated issuance process and commitment to security.

Trust, once lost, can be nearly impossible to regain. StartCom’s failure to regain a prominent browser’s trust led to the CA halting all certificate operations, a cautionary tale for every certificate authority. Service interruptions of this nature remain extremely rare for Let’s Encrypt. The organization typically prides itself on high availability and reliable automated systems.

The cross-signed certificate incident exemplifies the tremendous technical challenge of managing an aging root certificate infrastructure and possible transitions. Even when an organization deploys its infrastructure with good planning, there can be unanticipated issues associated with maintaining legacy equipment.

Security professionals encourage website administrators to evaluate their currently held certificates. They should verify certificates issued during the short window of May 8 against the expected root chain to ensure validity.

Let’s Encrypt’s quick response in halting issuance immediately upon discovering the problem demonstrates proper incident handling procedures. The organization prioritized user security over service availability, a decision that security professionals widely support.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts