EC-384 keys auto renew as DH-4096 instead of EC-384

Is this a case of DA needing to look into it? I don't want to point the finger to them right away, but I'm afraid I have to if I'm not the only one and it happens across 2 different OS-es

Regarding your edit on wednesday: I came here when the situation was already like this regarding the RPKI, although I wish I knew how the colleague before me set up those 2 servers. @Richard G
Last edited:
I just want to come back at this again.
Are we sure this is a Letsencrypt issue which we can report to @fln so by default not DH4096 but ECDHE is used on automatic certificates made by DA?
Because this is odd.