On May 13, Let's Encrypt's default "classic" ACME profile switched from its long-standing Generation X root hierarchy to a new one: Generation Y, consisting of two new root CAs and six new intermediates. The new roots are cross-signed by the existing Generation X roots (X1 and X2), so they're trusted anywhere the old ones already were — no compatibility gap for existing infrastructure. (If the idea of cross-signing and root/intermediate relationships is unfamiliar, our chain of trust guide covers how this hierarchy actually works.)
What's actually different about Generation Y
The headline change is what's missing: the new intermediates don't include the TLS Client Authentication EKU, continuing the industry-wide narrowing toward single-purpose certificates covered elsewhere in this year's news. Anyone still specifically needing that older, dual-purpose behavior can stay on the tlsclient profile, which remains on Generation X roots — though only until May 2026, after which that option goes away too.
Short-lived certificates: now for everyone
The same week's rollout also marked general availability for Let's Encrypt's short-lived certificate option — 6-day validity, aimed at fully automated environments that want to minimize the exposure window of a compromised key as much as technically possible. This was previously a more limited, early-access feature; it's now something any subscriber can opt into directly.
Why the timing lines up with everything else this year
Generation Y's rollout, the CA/Browser Forum's validity-shortening schedule, and Chrome's clientAuth distrust timeline are all pieces of the same coordinated industry direction — not independent decisions that happened to land in the same year. If you've been reading the rest of this year's SSL news, the pattern by now is probably obvious: shorter lifetimes, narrower certificate purposes, heavier reliance on automation.
This is our own summary and analysis of publicly reported news, written independently — not a reproduction of any single source's article. Where we reference a specific announcement, we link to it or name the organization directly.