Let’s Encrypt: some outdated devices will soon be incompatible
On 30 September 2021, a change will take place that will leave some devices that have not been updated unable to authenticate Let's Encrypt certificates. Here is what it means.
Let's Encrypt is communicating about this change by e-mail and in its documentation. However, the message can seem rather obscure to anyone who is not familiar with how TLS certificates work.
What is Let's Encrypt?
Let's Encrypt is a certificate authority. The certificates it issues free of charge allow anyone to run a website over HTTPS and to use SSL/TLS connections for all their services (e-mail, FTP, etc.). These connections are encrypted, and therefore secure, protecting you from any intruder on the network who could otherwise see the content of your connections.
What are CAs and what is the problem?
For your device to trust a certificate, a CA (certificate authority) must vouch for the legitimacy of the issuing organisation. And this CA must be present in the device's operating system (Windows, Linux, Mac OS, Android, iOS). However, CAs have an expiry date a few years ahead, so they need to be updated periodically.
Originally, Let's Encrypt used the "DST Root CA X3" CA, which gave it very broad support. This CA has already been replaced by "ISRG Root X1", but both are still available. The upcoming change therefore concerns the expiry of the old "DST Root CA X3" CA on 30 September 2021.
Although Let's Encrypt is doing everything it can to extend compatibility with older devices as far as possible, the oldest devices will become incompatible.
Which devices will be affected?
From the CAs supported by the various operating systems, we can work out which ones will soon no longer be compatible. As the affected devices are fairly old, few users should notice any change.
To support this change, you will need at least:
- Windows: XP SP3
- macOS: 10.12.1 (Sierra)
- Android: 2.3.6
- iPhone: iOS 10 (iPhone 5 and later)
- Linux: Ubuntu 16.04 / Debian 8 (with the ca-certificates packages updated)
- Firefox: 50.0
- Java: 8u141, 7u151
Notable incompatible devices and software include:
- Android: versions below 2.3.6, Cyanogen v9 and below, Jolla Sailfish OS below v1.1.2.16
- Kindle: below v3.4.1
- Blackberry: below 10.3.3
- PlayStation: PS4 below 5.0
- Nintendo: 3DS
- Software: Windows Live Mail 2012
Conclusion
Devices that have not been updated and will soon become incompatible are inherently insecure, and in any case should no longer be used for any personal or professional application involving your data. If you use one of these devices to browse the internet, this is an excellent reason to consider updating or replacing it before 30 September 2021.
