Is there any practical impact to this as someone who uses LE certificates on websites they host? It seems most like this is behind the scenes and doesn't directly impact security or validity of my own certificates.

https://bugzilla.mozilla.org/show_bug.cgi?id=2038351 "Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU"

#LetsEncrypt #ELI5

2038351 - Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU

ASSIGNED (pporada) in CA Program - CA Certificate Compliance. Last updated 2026-05-11.

@stylus nope, entirely inside baseball