Cloudflare SSL 证书即将改为 ISRG Root X1

2024-08-12 123 1

不久前接到CLoudflare 的邮件通知,被告知他们将在2024年9月9日,将现有的所有通过 Let’s Encrypt 颁发的 SSL 证书改为 ISRG Root X1链,以减少对所有设备的兼容性适配。

官方建议用户在CF上从行通过不同CA创建 SSL证书,比如推荐的CA:Google Trust Services

Cloudflare 原邮件

Hi, 

After September 9th, all Let’s Encrypt certificates issued through Cloudflare will start using the ISRG Root X1 chain resulting in a reduction of device compatibility. This will mainly impact connections from old Android devices (version 7.1.1 and earlier). To prevent this impact, we recommend re-issuingyour advanced certificates with a different CA, such as Google Trust Services. 

Impacted Domains & Next Steps 

To maintain the current level of device compatibility across all of your domains, we recommend re-issuing all advanced certificates currently using Let’s Encrypt as their certificate authority (CA) to use Google Trust Services instead. You can do this by clicking “Order Advanced Certificates” in the Edge Certificates tab in the Cloudflare dashboard and selecting Google Trust Services as your CA, or by making a POST request to the Advanced Certificates API endpoint with “google” in the certificate_authority parameter. 

Domains with Let's Encrypt certificates*:
bitestream.co, bite.dev
*displaying up to 100 domains

Total TLS 

If you are currently using Total TLS with Let’s Encrypt as the CA, we advise you to continue using Let’s Encrypt for now. Currently, switching Total TLS CAs requires disabling and re-enabling the feature, which results in the cleanup of existing TLS certificates before new ones are issued by the new CA. We are working on enabling a seamless CA switch for Total TLS that will only clean up the certificates issued from the old CA once the certificates from the new CA are successfully deployed. This functionality will be available after August 14th. We will notify all Total TLS users once it becomes available. Until then, we recommend continuing with your current CA. 

Note: Total TLS is only available to customers using Cloudflare as their DNS provider. 

Important Dates

  • September 9th, 2024: Cloudflare will rebundle all Let’s Encrypt certificates to use the ISRG Root X1 chain.
  • September 30th, 2024: The cross-signed CA chain will expire.

We previously informed customers that all Advanced certificates issued through Let’s Encrypt would experience a reduction in device compatibility after May 15th, 2024 due to the upcoming expiration of Let’s Encrypt cross-signed certificate chain. We have and will continue to serve the cross-sign chain until September 9th, 2024 to give our customers more time to prepare. 

If you have any questions, we recommend that you refer to our Developer Documentation or blog post regarding this change. 

Thank you for being a Cloudflare customer!

对此,我经过在CF portal 端用测试域名测试,发现如下规律:

  1. 在CF端如果一个域名创建了很多SSL证书,CF将默认使用最新的证书,其余的不被使用
  2. 如果一个域名最新的SSL证书是通过 Let’s Encrypt 颁发的,那么 CF 已经将他改为 ISRG Root X1链了(早于2024年9月9日已经开始实施)
  3. 如果一个域名同时具有3个月有效期和1年或更长有效期的SSL证书,CF将使用3个月有效期的证书

基于上述规律,我通过测试域名对 SSL CA 进行变更测试:为之前通过Let’s Encrypt 颁发SSL证书,并且当前已经是 ISRG Root X1链的域名,新建一个通过 Google Trust Services 颁发的证书

经过测试,已经能成功转变到使用新的 SSL 证书

ssl Certificate View
ssl Certificate View

结论: 通过“证书主题背景的备用名称”可以确认,是我新建的SSL证书

perfect

相关文章

Microsoft teams 连接器(connector)即将停用,但工作流(workflows)也不能用
使用 Helm 安装 metersphere 2.10.6-lts 版本

评论(1)

发布评论