{"id":13632,"date":"2020-12-01T16:53:19","date_gmt":"2020-12-01T21:53:19","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=13632"},"modified":"2023-04-10T17:24:35","modified_gmt":"2023-04-10T21:24:35","slug":"lets-encrypt-warns-of-reduced-compatibility-beginning-january-2021","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/lets-encrypt-warns-of-reduced-compatibility-beginning-january-2021\/","title":{"rendered":"Let\u2019s Encrypt Warns of Reduced Compatibility Beginning January 2021"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-an-expiring-root-certificate-means-1-in-3-android-devices-will-be-blocked-from-millions-of-sites-protected-by-let-s-encrypt\">An Expiring Root Certificate Means 1 in 3 Android Devices Will Be Blocked From Millions of Sites Protected by Let\u2019s Encrypt<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Editor&#8217;s Note: Since the publication of this article, Let&#8217;s Encrypt has come up with a solution that allows Android devices to maintain compatibility with their certificates. You can read more about it <a data-type=\"URL\" data-id=\"https:\/\/letsencrypt.org\/2020\/12\/21\/extending-android-compatibility.html\" href=\"https:\/\/letsencrypt.org\/2020\/12\/21\/extending-android-compatibility.html\">here<\/a>.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The new year is fast approaching, and with it comes some unfortunate news for users of Let\u2019s Encrypt certificates.&nbsp; Starting in January of 2021, compatibility with Let\u2019s Encrypt certificates will be reduced, impacting both website owners and users alike.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The impending issue is a result of Let\u2019s Encrypt no longer cross-signing with a third-party root certificate.&nbsp; Because of this switch, certain website visitors will be blocked from accessing websites that are secured with Let\u2019s Encrypt, and they\u2019ll be greeted with an error message similar to what you see below:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"609\" height=\"424\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/12\/Picture11.png\" alt=\"Let's Encrypt Expiring Root Certificate Warning\" class=\"wp-image-13674\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/12\/Picture11.png 609w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/12\/Picture11-300x209.png 300w\" sizes=\"auto, (max-width: 609px) 100vw, 609px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">It\u2019s certainly not something that users like to see when visiting a website.&nbsp; Similarly, site owners do not want anything presented that would raise doubts about the security and trust of their page.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, what exactly lead to this turn of events?&nbsp; Who will be affected by the change?&nbsp; And what can site owners do to mitigate the damage?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-the-issue\">Why the Issue?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The genesis of the problem goes all the way back to 2015, when Let\u2019s Encrypt was founded by the Internet Security Research Group (ISRG) and their various partners.&nbsp; Because their own root certificate could take years to be trusted by all the major browsers and operating systems, they cross-signed their certificates with an existing CA\u2019s trusted root.&nbsp; It\u2019s a typical course of action for new CAs, and in this case Let\u2019s Encrypt went with IdenTrust and their DST Root X3 certificate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This allowed Let\u2019s Encrypt to immediately start issuing certificates that would also be trusted across the internet.&nbsp; Fast forward to the present day however, and the IdenTrust DST Root X3 is getting closer and closer to its expiration date of September 30, 2021.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/12\/Picture2.png\" alt=\"Let's Encrypt Root Certificate Expiration\" class=\"wp-image-13635\" width=\"406\" height=\"511\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/12\/Picture2.png 405w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/12\/Picture2-238x300.png 238w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/12\/Picture2-75x94.png 75w\" sizes=\"auto, (max-width: 406px) 100vw, 406px\" \/><figcaption class=\"wp-element-caption\"><em>IdenTrust\u2019s Expiring Root Certificate, Used for Cross-Signing by Let\u2019s Encrypt<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s Encrypt did attempt to prepare themselves for this expiration event, issuing its own root certificate, ISRG Root X1.&nbsp; Unfortunately, though, it doesn\u2019t yet have the comprehensive trust that their soon-to-be-former IdenTrust root did.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite that fact, Let\u2019s Encrypt will begin issuing root certificates chained to their ISRG Root X1 certificate on <strong>January 11, 2021<\/strong>.&nbsp; Since their own root doesn\u2019t have the wide-ranging trust of the IdenTrust root, users on certain older platforms will be blocked from accessing any website that employs a Let\u2019s Encrypt SSL\/TLS certificate.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-exactly-is-affected\">Who Exactly Is Affected?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While the good news is that the issue primarily effects older platforms, the bad news is that there are still a very large number of people using them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most significant group affected is everyone that\u2019s using Android 7.1.1 or earlier.&nbsp; You might be wondering if anyone is still using such old versions, and the answer might surprise you \u2013 a total of 33.8% of all Android device are currently running them.&nbsp; And whenever they visit a Let\u2019s Encrypt-protected site (currently 225 million domains fall in this category), they\u2019ll encounter certificate errors and warning screens like we saw above.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s a difficult position for Let\u2019s Encrypt to find themselves in, and it\u2019s understandable considering the nature of the industry.&nbsp; Software update cycles can be glacial in their slowness, particularly with the Android operating system.&nbsp; It\u2019s nothing new, and the causes are difficult to remedy.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To be clear, the root problem here isn\u2019t Let\u2019s Encrypt\u2019s fault\u2014the real problem here is the slowness of software updates for many platforms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Manufacturers and\/or mobile carriers often modify the OS before loading it on to their own devices and passing them on to end-users. &nbsp;Thus, when Google releases updates to Android, the manufacturers and carriers can\u2019t simply just push the update on to their customers.&nbsp; They have to go back and incorporate the changes into their own proprietary software versions.&nbsp; Most of the time, especially for all but the newest devices, they just don\u2019t. In some cases, the phone hardware may not even be capable of running newer software versions. Which is why we currently have millions of Android devices with out-of-date operating systems floating around.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Older Java versions are also be affected by the root change.&nbsp; Any clients that are using Java versions prior to 1.8.0_141-b15 will receive warnings and\/or errors when encountering Let\u2019s Encrypt certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those are the main ones we know about so far, but as we\u2019ve seen previously with root expirations, more compatibility issues may arise with other platforms.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-recommended-actions\">Recommended Actions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Site owners have a few different options at their disposal as far as mitigating the impact of the root expiration.&nbsp; First off, you can warn visitors that are using older versions of Android that they need to upgrade before using your site.&nbsp; They can upgrade Android or switch their browser to Firefox Mobile thanks to the fact that it relies on its own (and regularly updated) list of root certificates, rather than that of the operating system\u2019s.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While this is a great remedy in theory, it\u2019s also unlikely to be very effective since most users won\u2019t want to go through the trouble of upgrading their device or switching browsers just to visit a site.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You could also stop supporting older versions.&nbsp; However, this could lead to frustrated users, an uptick in support requests, and lost revenue from reduced traffic.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Site owners that use ACME can modify their client settings to continue to use the cross-signed Let\u2019s Encrypt certificates.&nbsp; However, this will only work until September 2021.&nbsp; It can buy you some time to get your long-term solution in place, though.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most practical solution that doesn\u2019t require any action on the user\u2019s end is to switch to a CA with ubiquitous roots that are trusted by all major platforms (including older systems).\u00a0Certificates from trusted and established authorities have used their own trusted roots for many years and cross sign using their own older roots to ensure full compatibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Tip:<\/strong> if you\u2019re not sure how this will impact your website users, you can use Google Analytics to identify how many of your site users are using Android 7.1.1 or older. Our website gets about 4,000 visits per month from people using these older versions of Android, but the impact may vary depending on the audience your site targets.\u00a0<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-moving-forward\">Moving Forward<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s Encrypt will start using their new, less-trusted root in just over a month, so it\u2019s best to figure out how you\u2019re going to proceed as soon as possible.&nbsp; Especially since nearly one-third of all Android devices will be affected.&nbsp; No option is perfect.&nbsp; You can put the onus on your users, but then you\u2019re depending on them to upgrade their devices or else be blocked from your site.&nbsp; Or you can switch to a CA with a root that\u2019s fully trusted on both new and old devices.&nbsp; It requires some effort on your end, but that seems a small price to pay to maintain the trust you\u2019ve built with your userbase and take the problem off their laps.&nbsp; Either way, make sure you\u2019re prepared for January 11!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An Expiring Root Certificate Means 1 in 3 Android Devices Will Be Blocked From Millions of Sites Protected by Let\u2019s Encrypt Editor&#8217;s Note: Since the publication of this article, Let&#8217;s&#8230;<\/p>\n","protected":false},"author":37,"featured_media":13633,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,130,17],"tags":[],"class_list":["post-13632","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-everything-encryption","category-industry-lowdown","post-without-tags"],"views":13319,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/12\/bigstock-Glowing-Neon-Line-Broken-Or-Cr-394561904.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13632","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=13632"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13632\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/13633"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=13632"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=13632"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=13632"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}