Return-path: Envelope-to: lojban@lojban.org Delivery-date: Fri, 15 Mar 2024 01:00:40 -0700 Received: from mta-70-53-53.sparkpostmail.com ([156.70.53.53]:9189) by 64c5cd764d82 with esmtps (TLS1.2) tls TLS_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1rl2UW-000qyF-2u for lojban@lojban.org; Fri, 15 Mar 2024 01:00:39 -0700 X-MSFBL: kzjNRzPd7tVRag4vEKN4+pEhGBP00ZSKRzr9NOKHbYA=|eyJjdXN0b21lcl9pZCI 6IjI4MDE3MiIsInN1YmFjY291bnRfaWQiOiIzOTkiLCJyIjoibG9qYmFuQGxvamJ hbi5vcmciLCJ0ZW5hbnRfaWQiOiJzcGMiLCJtZXNzYWdlX2lkIjoiNjVlZjIwMDB mNDY1NDIwOTliOGIifQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=em1.cloudflare.com; s=scph0124; t=1710489632; i=@em1.cloudflare.com; bh=/hpWOnhpFRYWCDDmD+xgSsylcPTsfPzE87EvvOKmeOs=; h=To:Message-ID:Date:Content-Type:From:Subject:From:To:Cc:Subject; b=j/7FFIgoev5Lei2JRg5Ye2WiftuWlcBnnGPN97h830hFnVMZdpLQBan9K09D7xVCI qMQD59YS+U46muv7Z2p7wTP755jw2cnjcN4yOCAecxpkZJnzZ0fT/uytD0B/KurM/+ nOJwlNGeZ8ziiF/7S35nM8vu2uq4c6AYr0p+Ntp0= To: lojban@lojban.org Message-ID: Date: Fri, 15 Mar 2024 08:00:32 +0000 Content-Type: multipart/alternative; boundary="_----SLZzO25d7RmZ7zrs19GwTQ===_79/B8-22863-02004F56" MIME-Version: 1.0 Reply-To: em@em1.cloudflare.com X-Campaign-ID: 9296192 From: "Cloudflare" Subject: [Cloudflare - Action Required] Upcoming Let's Encrypt certificate chain change X-Message-ID: 6b9e6fcfa3aa48419348f29dd6ec17f3 X-Feedback-ID: 12292333:9296192:46499:iterable Feedback-ID: 12292333:9296192:46499:iterable X-Spam-Score: 0.7 (/) X-Spam_score: 0.7 X-Spam_score_int: 7 X-Spam_bar: / X-Spam-Report: Spam detection software, running on the system "50bab00d4276", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see @@CONTACT_ADDRESS@@ for details. Content preview: [Cloudflare - Action Required] Upcoming Let's Encrypt certificate chain change  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ [...] Content analysis details: (0.7 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60% [score: 0.5000] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: cloudflare.com] 0.0 URIBL_ZEN_BLOCKED_OPENDNS ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ [URIs: stripocdn.email] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record 0.0 SPF_NONE SPF: sender does not publish an SPF Record 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to background -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.0 T_KAM_HTML_FONT_INVALID Test for Invalidly Named or Formatted Colors in HTML --_----SLZzO25d7RmZ7zrs19GwTQ===_79/B8-22863-02004F56 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable [Cloudflare - Action Required] Upcoming Let's Encrypt certificate chain cha= nge =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80= =87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F = =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87= =CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2= =80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD= =8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80= =87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F = =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87= =CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2= =80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD= =8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80= =87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F = =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87= =CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2= =80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD= =8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80= =87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F = =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87= =CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2= =80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD= =8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80= =87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F = =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87= =CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2= =80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD= =8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80= =87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F = =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87= =CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2= =80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD= =8F Upcoming Let's Encrypt certificate chain change Hi, We are reaching out= to inform you about an upcoming change that will impact the device compati= bility of Let=E2=80=99s Encrypt certificates issued after May 15th, 2024. W= e are reaching out to you because we identified that you are currently usin= g Let=E2=80=99s Encrypt certificates through Universal SSL, Advanced Certif= icate Manager, Custom Certificates, or SSL for SaaS. We recommend that you = familiarize yourself with the Let=E2=80=99s Encrypt change and make any nec= essary adjustments ahead of time. Change Overview Let=E2=80=99s Encrypt iss= ues certificates through two chains: the ISRG Root X1 chain and the ISRG Ro= ot X1 chain cross-signed by IdenTrust=E2=80=99s DST Root CA X3. The cross-s= igned chain has allowed Let=E2=80=99s Encrypt certificates to become widely= trusted, while the pure chain developed compatibility with various devices= over the last 3 years, growing the number of Android devices trusting ISRG= Root X1 from 66% to 93.9%. Let=E2=80=99s Encrypt announced that the cross-= signed chain is set to expire on September 30th, 2024. As a result, Cloudfl= are will stop issuing certificates from the cross-signed CA chain on May 15= th, 2024. Impact The expiration of the cross-signed chain will primarily af= fect older devices (e.g. Android 7.0 and earlier) and systems that solely r= ely on the cross-signed chain and lack the ISRG Root X1 chain in their trus= t store. This change could result in certificate validation failures on the= se devices, potentially leading to warning messages or access problems for = users visiting your website. Impact to certificates issued through Universa= l SSL, Advanced Certificate Manager, or SSL for SaaS: To prepare for the CA= expiration, after May 15th, Cloudflare will no longer issue certificates f= rom the cross-signed chain. Certificates issued before May 15th will contin= ue to be served to clients with the cross-signed chain. Certificates issued= on May 15th or after will use the ISRG Root X1 chain. Additionally, this c= hange only impacts RSA certificates. It does not impact ECDSA certificates = issued through Let=E2=80=99s Encrypt. ECDSA certificates will maintain the = same level of compatibility that they have today. Impact to certificates up= loaded through Custom Certificates: Certificates uploaded to Cloudflare are= bundled with the certificate chain that Cloudflare finds to be the most co= mpatible and efficient. After May 15th, 2024, all Let=E2=80=99s Encrypt cer= tificates uploaded to Cloudflare will be bundled with the ISRG Root X1 chai= n, instead of the cross-signed chain. Certificates uploaded before May 15th= will continue to use the cross-signed chain until that certificate is rene= wed. Important Dates May 15th, 2024: Cloudflare will stop issuing certifica= tes from the cross-signed CA chain. In addition, Let=E2=80=99s Encrypt Cust= om Certificates uploaded after this date will be bundled with the ISRG X1 c= hain instead of the cross-signed chain. September 30th, 2024: The cross-sig= ned CA chain will expire. Recommendations: To reduce the impact of this cha= nge, we recommend taking the following steps: Change CAs: If your customers= are making requests to your application from legacy devices and you expect= that this change will impact them, then we recommend using a different cer= tificate authority or uploading a certificate from the CA of your choice. M= onitoring: Once the change is rolled out, we recommend monitoring your supp= ort channels for any inquiries related to certificate warnings or access pr= oblems. Update Trust Store: If you control the clients that are connecting = to your application, we recommend upgrading the trust store to include the = ISRG Root X1 chain to prevent impact. If you have any questions, we recomme= nd that you refer to our Developer Documentation or blog post regarding thi= s change. If you are an Enterprise customer and have additional questions o= r concerns, please reach out to your Account Team. Cloudflare Dashboard Upg= rade Plan Login Visit Community THIS IS A SERVICE-RELATED EMAIL This email = was sent because you are a Cloudflare customer or requested information abo= ut Cloudflare services. Copyright =C2=A9 2024 Cloudflare, Inc. 101 Townsend= Street, San Francisco, CA 94107 Unsubscribe --_----SLZzO25d7RmZ7zrs19GwTQ===_79/B8-22863-02004F56 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset="UTF-8" [Cloudflare - Action Required] Upcoming Let's Encrypt c= ertificate chain change =0D=0A
<= img border=3D"0" width=3D"1" height=3D"1" src=3D"http://tracksp.cloudflare.= com/q/qA9NHnwKXZ7Nu9Mql3jTIQ~~/AARGbAA~/RgRn1oUgPVcDc3BjQgpl7yAA9GVCCZuLUhF= sb2piYW5AbG9qYmFuLm9yZ1gEAAABjw~~" alt=3D""/>
=0D=0A=E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F= =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87= =CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2= =80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD= =8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80= =87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F = =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87= =CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2= =80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD= =8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80= =87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F =E2=80=87=CD=8F  ͏ = 199;͏  ͏  ͏  ͏  ͏  &= #847;  ͏  ͏  ͏  ͏  ͏=  ͏  ͏  ͏  ͏  ͏ Q= 99;͏  ͏  ͏  ͏  ͏  &#= 847;  ͏  ͏  ͏  ͏  ͏ =  ͏  ͏  ͏  ͏  ͏ ̳= 9;͏  ͏  ͏  ͏  ͏  = 47;  ͏  ͏  ͏  ͏  ͏ &= #8199;͏  ͏  ͏  ͏  ͏  = ;͏  ͏  ͏  ͏  ͏  T= 7;  ͏  ͏  ͏  ͏  ͏ &#= 8199;͏  ͏  ͏  ͏  ͏  = ͏  ͏  ͏  ͏  ͏  ͏= ;  ͏  ͏  ͏  ͏  ͏ = 199;͏  ͏  ͏  ͏  ͏  &= #847;  ͏  ͏  ͏  ͏  ͏=  ͏  ͏  ͏  ͏  ͏ Q= 99;͏  ͏  ͏  ͏  ͏  &#= 847;  ͏  ͏  ͏  ͏  ͏ =  ͏  ͏  ͏  ͏  ͏ ̳= 9;͏  ͏  ͏  ͏  ͏  = 47;  ͏  ͏  ͏  ͏  ͏ &= #8199;͏  ͏  ͏  ͏  ͏  = ;͏  ͏  ͏  ͏  ͏  T= 7;  ͏  ͏  ͏  ͏  ͏ &#= 8199;͏  ͏  ͏ =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD = =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2= =AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD = =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2= =AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD = =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2= =AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD = =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2= =AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD = =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2= =AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD = =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2= =AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD = =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD =C2=AD  
<= /td>
=
=

Upcoming Let's Encrypt certificate chain change

=
<= /tr>
= =

Hi, 


We are reaching out to inform= you about an upcoming change that will impact the device compatibility of = Let=E2=80=99s Encrypt certificates issued after May 15th, 2024. We are reac= hing out to you because we identified that you are currently using Let=E2= =80=99s Encrypt certificates through Universal SSL, Advanced Certificate Ma= nager, Custom Certificates, or SSL for SaaS. We recommend that you familiar= ize yourself with the Let=E2=80=99s Encrypt change and make any necessary a= djustments ahead of time. 


Change Overview

<= p style=3D"Margin:0;-webkit-text-size-adjust:none;-ms-text-size-adjust:none= ;mso-line-height-rule:exactly;font-family:-apple-system, BlinkMacSystemFont= , 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'S= egoe UI Emoji', 'Segoe UI Symbol';line-height:24px;color:#333333;font-size:= 16px">Let=E2=80=99s Encrypt issues certificates through two chains: the ISR= G Root X1 chain and the ISRG Root X1 chain cross-signed by IdenTrust=E2=80= =99s DST Root CA X3. The cross-signed chain has allowed Let=E2=80=99s Encry= pt certificates to become widely trusted, while the pure chain developed co= mpatibility with various devices over the last 3 years, growing the number = of Android devices trusting ISRG Root X1 from 66% to 93.9%. 


<= p style=3D"Margin:0;-webkit-text-size-adjust:none;-ms-text-size-adjust:none= ;mso-line-height-rule:exactly;font-family:-apple-system, BlinkMacSystemFont= , 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'S= egoe UI Emoji', 'Segoe UI Symbol';line-height:24px;color:#333333;font-size:= 16px">Let=E2=80=99s Encrypt announced that the cross-signed chain is set to expire on Sep= tember 30th, 2024. As a result, Cloudflare will stop issuing certificate= s from the cross-signed CA chain on May 15th, 2024


The expiration of the cross-signed chain will pr= imarily affect older devices (e.g. Android 7.0 and earlier) and systems tha= t solely rely on the cross-signed chain and lack the ISRG Root X1 chain in = their trust store. This change could result in certificate validation failu= res on these devices, potentially leading to warning messages or access pro= blems for users visiting your website. 


Impact to ce= rtificates issued through Universal SSL, Advanced Certificate Manager, or S= SL for SaaS: 

To prepare for the CA expiration, after M= ay 15th, Cloudflare will no longer issue certificates from the cross-signed= chain. Certificates issued before May 15th will continue to be served to c= lients with the cross-signed chain. Certificates issued on May 15th or afte= r will use the ISRG Root X1 chain. Additionally, this change only impacts R= SA certificates. It does not impact ECDSA certificates issued through Let= =E2=80=99s Encrypt. ECDSA certificates will maintain the same level of comp= atibility that they have today.  


Impact to cer= tificates uploaded through Custom Certificates: 

Certif= icates uploaded to Cloudflare are bundled with the certificate chain that C= loudflare finds to be the most compatible and efficient. After May 15th, 20= 24, all Let=E2=80=99s Encrypt certificates uploaded to Cloudflare will be b= undled with the ISRG Root X1 chain, instead of the cross-signed chain. Cert= ificates uploaded before May 15th will continue to use the cross-signed cha= in until that certificate is renewed. 


Important Dat= es


May 15th, 2024: Cloudflare will stop issuing ce= rtificates from the cross-signed CA chain. In addition,  Let=E2= =80=99s Encrypt Custom Certificates uploaded after this date will be bundle= d with the ISRG X1 chain instead of the cross-signed chain. 

September 30th, 2024: The cross-signed CA chain wil= l expire. 


Recommendations: 

To r= educe the impact of this change, we recommend taking the following steps:&n= bsp;

  1. Change CAs: If = your customers are making requests to your application from legacy devices = and you expect that this change will impact them, then we recommend using a dif= ferent certificate authority or uploading a certificate from th= e CA of your choice. 

  2. = Monitoring: Once the change is rolled out, we recommend monitoring y= our support channels for any inquiries related to certificate warnings or a= ccess problems.  

  3. Update Trust Store: If you control the clients that are connecting = to your application, we recommend upgrading the trust store to include the = ISRG Root X1 chain to prevent impact. 

If you ha= ve any questions, we recommend that you refer to our Developer Documentation or blog p= ost regarding this change.  If you are an Enterprise cust= omer and have additional questions or concerns, please reach out to your Ac= count Team.


Cloudflare Dashboar= d
=
=0D=0A3D""=0D=0A --_----SLZzO25d7RmZ7zrs19GwTQ===_79/B8-22863-02004F56--