we are currently using the main chain provided by GTS via the ACME API:
Certificate chain 0 s:CN = upload.wikimedia.org i:C = US, O = Google Trust Services, CN = WR1 a:PKEY: id-ecPublicKey, 256 (bit); sigalg: RSA-SHA256 v:NotBefore: Jun 17 15:07:47 2025 GMT; NotAfter: Sep 15 15:07:46 2025 GMT 1 s:C = US, O = Google Trust Services, CN = WR1 i:C = US, O = Google Trust Services LLC, CN = GTS Root R1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Dec 13 09:00:00 2023 GMT; NotAfter: Feb 20 14:00:00 2029 GMT 2 s:C = US, O = Google Trust Services LLC, CN = GTS Root R1 i:C = BE, O = GlobalSign nv-sa, OU = Root CA, CN = GlobalSign Root CA a:PKEY: rsaEncryption, 4096 (bit); sigalg: RSA-SHA256 v:NotBefore: Jun 19 00:00:42 2020 GMT; NotAfter: Jan 28 00:00:42 2028 GMT ---
GTS also offers a shorter chain that assumes that GTS Root R1 is trusted by the user-agent, we need to check its availability to consider the change
