Earlier quoted context omitted.
It is explicitly not a replacement, but some kind of legacy fallback that they don't want you to use, but exists for enterprise customers that absolutely can't get trust.
Are you sure? That's the path that InCommon has been providing me for new certificates since they switched away from the expiring one.
- Leaf cert (your cert)
- InCommon RSA Server CA
- USERTrust RSA Certification Authority (this is/should be the final point)