Top websites see outages as Let's Encrypt's CA certificate expires

System outage in red on a computer keyboard
(Image credit: Shutterstock/hafakot)

One of the biggest non-profit Certificate Authorities (CA) services is experiencing high levels of renewals from websites and apps, with some big name sites seeing significant outages.

Due to its cross-signed DST Root CA X3 expiring yesterday, Let’s Encrypt's issue, which is run by the Internet Security Research Group, left websites and apps such as Shopify and Slack experiencing outages and errors such as devices failing to establish secure connections to remote systems.

In a Twitter post, Let’s Encrypt advised those affected with errors on their site or app to consult its community forum, but offered no promise of a speedy resolution in getting certificate renewals. 

CA root expired

All certificates that power HTTPS on the web are issued by a trusted CA recognised by a device or operating system.

Built into an operating system, it is usual procedure for these certificates to be updated while features on an operating system or device are being reformed.

When the root certificate expires, it’s almost impossible for websites and apps to not fail, and outages and errors are almost impossible to avoid.

TechRadar Pro reached out to Let’s Encrypt for an update on what is going to happen next and how this can be avoided as expiration dates are known in advance and should be invisible to software, services, and users.

There are three types of certificates:

1. End-entity certificates, the ones that websites get. Typically valid for between 90 days and a year.

2. Intermediate certificates, used to issue end-entity certificates. Typically valid for around 3-6 years.

3. Root certificates, used to issue intermediate certificates and trusted directly by browsers and operating systems. Typically valid for around 20 years, which is why root expirations are rare events.

Let's Encrypt's Executive Director, Josh Aas, told TechRadar Pro that when end-entity certificates expire there is typically no widespread impact, it only pertains to a small number of sites and they just renew before expiration.

"When intermediate certificates expire it can impact any sites that used certificates issued by them, but sites can typically fix the problem easily," he added.

"When root certificates expire there can be more widespread impact because client operating systems or browsers may need to be upgraded to fix problems. That isn't always an option for older devices or deployments.

"We had an intermediate certificate expire on Wednesday, followed by a commonly used root expiring on Thursday. Those expirations led to some sites having issues serving their visitors. The solution is for servers to move to newer certificates (which have been available from Let's Encrypt for some time now) and for clients to get updates such that they trust newer certificates. That doesn't always happen though, for a variety of reasons, so some things break."

We were also told that Slack's outage was caused by a problem with their DNSSEC, rather than a certificate problem.

With millions of websites relying on Let's Encrypt services, affected parties took to Twitter to share advice with others struggling to get their site running again without errors. Some have been forced to update their systems or manually install Let’s Encrypt’s certificate.

This is not the first time a CA root has expired. In May 2020, last year, the AddTrust External CA Root expired and caused a number of outages as a result.

Via The Register

Abigail Opiah
B2B Editor - Web hosting & Website builders

Abigail is a B2B Editor that specializes in web hosting and website builder news, features and reviews at TechRadar Pro. She has been a B2B journalist for more than five years covering a wide range of topics in the technology sector from colocation and cloud to data centers and telecommunications. As a B2B web hosting and website builder editor, Abigail also writes how-to guides and deals for the sector, keeping up to date with the latest trends in the hosting industry. Abigail is also extremely keen on commissioning contributed content from experts in the web hosting and website builder field.

Read more
A close-up of an interent search bar with 'http://ww' visible
Let’s Encrypt halts expiration alerts - but it's for a good reason
Padlock against circuit board/cybersecurity background
Best SSL certificate service of 2025
vpn
Nominet says it was hit by cyberattack following recent Ivanti VPN security issue
Security
Experts warn millions of email servers could be vulnerable to attack
A digital representation of a lock
The true threat of business downtime
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)