- Let’s Encrypt halted all certificate issuance for about two and a half hours on May 8 – this was after discovering a cross-signed root certificate problem affecting its Generation Y root transition.
- The organization rolled back two certificate profiles (tlsserver and shortlived) to the Generation X root following the incident, which occurred just five days before major planned platform changes.
- Three scheduled updates, including 45-day certificates, remain on track for May 13, pending full resolution of the root certificate issue, though Let’s Encrypt has not disclosed whether any incorrect certificates were issued.
Let’s Encrypt temporarily stopped issuing digital certificates on May 8, 2026, after engineers discovered a serious problem involving a cross-signed root certificate. The organization suspended all issuance across both its production and testing systems before restoring services later that same day.
The incident began at 18:37 UTC when company engineers identified a potential security issue. They immediately halted all certificate generation as a safety measure. The impacted systems were the production and staging ACME API endpoints, as well as two high-assurance data center portals.
Let’s Encrypt confirmed that certificate services returned to normal operation at approximately 21:03 UTC, approximately 2 and a half hours after the initial shutdown. In addition, Let’s Encrypt has rolled back all certificate generations to Generation X Root because of a cross-signature certificate issue.
Generation Y Root Transition Hit Technical Snag Just Days Before Planned Launch
This incident purportedly has some major implications associated with its timing. Let’s Encrypt has already announced the following three significant platform changes to occur on May 13, 2026, just five days before the related project shutdown.
One planned change relates to the tlsserver ACME profile. It proposes the issuance of 45-day certificates as part of Let’s Encrypt long term goal to cut down the present 90-day to 45-day certificate lifetimes over the next two years.
Another update affects the TLS client profile, which is used for authenticating TLS client certificates. The organization will restrict this profile completely to ACME accounts that have issued past request of certificates from the service. Full support for TLS client certificates will end on July 8, 2026.
The typical ACME profile also faced a scheduled transition to the Generation Y intermediates. These new intermediates will now link to the current X1 and X2 roots and are necessary for continued interoperability across client environments whenever they are implemented.
All three intended changes were in a running state on Let’s Encrypt’s staging environment at the time of the incident. The company stated that this incident will not impact the deployment of the planned production rollout on May 13, while they work on resolving the root certificate issue
Two Certificate Profiles Remain Rolled Back to Generation X Root
The root certificate problem directly impacts two specific profiles of ACME certificates. The short-lived and TLS server profiles now fall under the Generation X root following the rollback.
Let’s Encrypt has not disclosed whether any incorrectly issued certificates reached users before the organization halted issuance. The company remains tight-lipped about the exact nature of the cross-signed certificate issue that triggered the shutdown.
The Generation X root represents older infrastructure for the certificate authority. The Generation Y root, previously scheduled for activation, would have offered updated security features and improved compatibility with modern systems.
Administrators who rely on automated ACME-related renewal workflows should pay close attention to their systems. Those using the short-lived or TLS server profiles need to monitor renewal logs carefully. They should verify that any certificates issued around the May 8 window chain correctly to the expected root certificate.
Let’s Encrypt continues to provide updates and community support through its official community forum. Also, the organization asks users to report any certificate anomalies they detect following the incident.
Certificate Authority Faces Scrutiny After Rare Service Disruption
Let’s Encrypt operates as one of the world’s largest certificate authorities, providing free SSL/TLS certificates to millions of websites. The organization has earned widespread trust for its automated issuance process and commitment to security.
Trust, once lost, can be nearly impossible to regain. StartCom’s failure to regain a prominent browser’s trust led to the CA halting all certificate operations, a cautionary tale for every certificate authority. Service interruptions of this nature remain extremely rare for Let’s Encrypt. The organization typically prides itself on high availability and reliable automated systems.
The cross-signed certificate incident exemplifies the tremendous technical challenge of managing an aging root certificate infrastructure and possible transitions. Even when an organization deploys its infrastructure with good planning, there can be unanticipated issues associated with maintaining legacy equipment.
Security professionals encourage website administrators to evaluate their currently held certificates. They should verify certificates issued during the short window of May 8 against the expected root chain to ensure validity.
Let’s Encrypt’s quick response in halting issuance immediately upon discovering the problem demonstrates proper incident handling procedures. The organization prioritized user security over service availability, a decision that security professionals widely support.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
Google and FBI Disrupt NetNut Residential Proxy Network Used by 2M+ Devices
Google worked with the FBI and Lumen to disrupt the NetNut residential proxy network, also known as ...
Opera Launches Paste Protect to Block ClickFix Clipboard Attacks
Opera’s Paste Protect blocks harmful commands from reaching the clipboard, preventing ClickFix...
Reddit Introduces Mandatory Age Verification for EU Teens Accessing NSFW Content
Reddit will require European Union users under 18 to verify their age before viewing mature or NSFW ...
Popular ‘Adblock for YouTube’ Chrome Extension Found With Remote Code Execution Risk
The popular “Adblock for YouTube” Chrome extension now carries an architectural weakness...
Texas Hunting and Fishing License Data Breach Affects 3 Million Customers
Approximately 3 million Texas hunting and fishing license customers were affected by a data breach i...
FBI Warns of ‘Kali365’ Subscription Service Targeting Microsoft 365 Accounts
The FBI’s sounding the alarm on Kali365, a site where criminals can pick up ready-to-use tools for s...