Skip navigation

The upcoming Let's Encrypt update and its impact on Android devices

Marcus AsshauerMarcus AsshauerSenior System Engineer · synaigy

2 min read

Die bevorstehende Let's Encrypt Aktualisierung

The world of the internet is constantly changing, and as an online shop operator, it is essential to keep pace with the latest developments in web technology. In this context, the upcoming renewal of Let's Encrypt certificates, due on 30 September 2024, comes into focus. Recent years have been shaped by adjustments and security measures, and it is time to take a look at the upcoming transition.

Let's Encrypt and cross-signing

Let's Encrypt is a non-profit certificate authority that provides free SSL/TLS certificates. These certificates are essential for the secure transmission of data between the web server and the users of a website. They ensure that the transmitted information is encrypted, protecting against potential security risks such as data misuse and unauthorised access.

The initiative aims to promote the spread of secure connections on the internet, and its certificates are used by many websites worldwide. By providing certificates free of charge, Let's Encrypt also gives small businesses and private website operators access to secure communication on the web.

Back in the middle of last year, Let's Encrypt announced an important change to the renewal of the new root certificates. In 2021, a cross-signing procedure was used to ensure support for older Android devices. Now the next certificate renewal is due, and the transition begins on 8 February 2024.

This strategic decision gives website operators ample time to renew their certificates and ensure their websites continue to be seamlessly supported by current browsers. It should be noted, however, that older Android devices running version 7.0 and earlier will no longer be considered in this transition.

Recommendations for action for shop operators

To ensure your online shop navigates the certificate transition smoothly, shop operators should make intensive use of their shop's analytics tools over the coming weeks. Closely monitoring possible traffic drops can flag issues early on. Ideally, website statistics should be actively evaluated to determine whether Android 7.0 and older is relevant for the target audience.

In case older Android devices make up a significant share of your target audience, installing Firefox Mobile offers itself as the simplest solution. This mobile browser has its own certificate store and doesn't fall back on outdated stores from the operating system.

If in doubt, shop operators shouldn't hesitate to get in touch and discuss individual solutions.

 

The upcoming Let's Encrypt certificate renewal requires a proactive approach from shop operators. Understanding the impact on older Android devices and adapting strategies early are crucial to ensuring a smooth transition. Let's Encrypt's support not only contributes to security on the internet, but also enables comprehensive access to encrypted connections for all users.

If you're not sure whether your shop needs adjustments, contact us and we'll help you further.

Source: https://letsencrypt.org/2023/07/10/cross-sign-expiration

Subscribe to the blog now and never miss any news

✔️free of charge ✔️weekly news ✔️expert knowledge

Please accept the corresponding cookies to view this embedded content.