Certificate authority Let's Encrypt says it has found a workaround that will extend older Android phones' compatibility with its certificates by three years
When you haven't been updated since 2016, expiring certificates are a problem. — Things were touch-and-go for a while …
Context & Ripple Effects
In November, Let's Encrypt warned that phones running Android 7.1 or older would stop trusting its root certificate once it expired in 2021 — meaning those devices would suddenly fail on any site secured by what is effectively the default free CA for the web. The problem traced back to devices that haven't received updates since around 2016, part of the same long tail of unpatched Android hardware that has been exploited by malvertising and drive-by campaigns for years.
The workaround announced today buys three more years of compatibility, converting an imminent mass-breakage event into a deferred deadline. It matters because Let's Encrypt issues certificates at such scale that losing trust on old Androids would have hit site operators everywhere, not just niche services.
First-order effects
- Operators of sites using Let's Encrypt certificates no longer face a 2021 cliff where Android 7.1-and-older visitors see connection errors; the workaround keeps those devices trusting its certs for three additional years.
- Owners of aging Android phones keep working access to secure websites without needing an OS update they were never going to receive.
Second-order effects
- Site operators who had begun budgeting for a switch to alternative certificate authorities — or for dropping encryption support on legacy clients — can hold off, reducing near-term churn toward commercial CAs.
- Google and device makers face renewed scrutiny over Android's update lifecycle: the episode shows that when a major root expires, the cost of fragmented, short-lived software support lands on the entire web, not just the phone vendors.
Third-order effects
- If root expirations keep colliding with un-updated device fleets, the web PKI will structurally need longer-lived legacy chains and cross-signing workarounds as standard practice — maintenance burden that falls on CAs like Let's Encrypt rather than on manufacturers.
- The three-year reprieve also extends the security exposure window for devices already known to be vulnerable, since the same un-updated population targeted by drive-by exploits stays online longer instead of being forced off the modern web.
The trend: Web certificate authorities are increasingly absorbing the cost of Android's fragmented update model, patching over expired-trust cliffs for device fleets their own vendors have abandoned.