Let's Encrypt Stopping Issuance (RESOLVED)

Last Updated: 2026-05-09T00:46:27Z

What Happened

Earlier today, Let’s Encrypt issuance stopped with the following message:

We have been made aware of a potential incident and are shutting down all issuance.

As of now, issuance has resumed.

Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our “tlsserver” and “shortlived” ACME certificate profiles.

Cloudflare was also impacted during this outage.

This incident is resolved. To see how the story evolved, click the orange “edit” icon at the top right of the post.

A complete incident report is here:

Let’s Encrypt’s Gen Y (YE and YR bulleted below) Cross-Certified Subordinate CAs were issued in violation of CCADB policy which requires that the serverAuth EKU extension MUST be present in cross-signed intermediate certificates issued since June 15th 2025. Root YE and YR were issued September 3rd 2025 and are subject to the requirements.

3 Likes

Unclear what “compliance” issue could bring down all issuance, or what “shortly” means.

I guess we have to be patient.

Failed cross-sign when between Generation X and Generation Y root, forcing a rollback.

Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our “tlsserver” and “shortlived” ACME certificate profiles.

4 Likes

Added final Bugzilla incident report.