You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, under Subordinate CA Certificate, we require that the Subject Distinguished Name has values:
C=US, O=Let's Encrypt, CN=Let's Encrypt Authority X; or
C=US, O=Let's Encrypt, CN=[ER]
where n is an integer representing the instance of the Subordinate CA Certificate.
While this accurately models our current names, it's a bit over-constrained: We may want to use different letter designators in the future, for example.
We should change this to allow any unique identifier per subordinate CA certificate
The text was updated successfully, but these errors were encountered:
- Remove OCSP Delegated Responder profile, as we no longer issue such certificates
- Remove restrictions on the Common Names we set
- Remove restriction on ECDSA P-521
- Miscellaneous formatting and phrasing improvements
Fixes#185Fixes#196Fixes#212Fixes#217Fixes#218
Currently, under Subordinate CA Certificate, we require that the Subject Distinguished Name has values:
C=US, O=Let's Encrypt, CN=Let's Encrypt Authority X; or
C=US, O=Let's Encrypt, CN=[ER]
where n is an integer representing the instance of the Subordinate CA Certificate.
While this accurately models our current names, it's a bit over-constrained: We may want to use different letter designators in the future, for example.
We should change this to allow any unique identifier per subordinate CA certificate
The text was updated successfully, but these errors were encountered: