Let's Encrypt DST Root CA X3 has expired
twitter.com
twitter.com
In particular these two problems don't seem to have been spotted ahead of time:
Android Dns-over-TLS trouble https://community.letsencrypt.org/t/android-devices-with-dot...
Trouble with Electron applications https://community.letsencrypt.org/t/issues-with-electron-and...
The primary problem in most cases is the full chain cert not being updated or used in your configuration.
1. Your Let’s Encrypt script might be outdated and isn’t pulling the down the new chain file. This could be your first problem.
2. Your configuration for Apache or whatever app your using is referencing a chain file that isn’t the current one. This could be your second problem. It’s possible you copied the chain file somewhere a long time ago and have been referencing that one instead of the new one that gets pulled down.
The problem will be confusing because your cert will be current, but it still won’t be trusted.
Something like Dovecot can actually use the full chain cert file as the cert file. This will solve that problem instead of only referencing the .crt file, which won’t help, because it won’t be trusted. The full chain needs to be used.
[^1] https://community.letsencrypt.org/t/openssl-client-compatibi...
https://status.cloud.google.com/ >>>Global: We have identified an issue affecting "Uptime Checks" within Google Cloud Monitoring, impacting customers using "Let's Encrypt" 3rd party certificates.
it generated a scary amount of alerts, almost finished fueling the single-engine before I realized what the problem was.
This includes the Nextcloud client for Windows and the DNS over TLS implementation in Android 11.
Adding the argument --preferred-chain "ISRG Root X1" to certbot fixes this by not chaining the expired CA X3...
Since they were on node v10 they stopped being able to talk to letsencrypt SSL sites today. Since AWS has stopped supporting v10 we couldn't upgrade them to the minor version of v10 that supports the CA
Luckily this was quick to fix by just renewing the server cert without the DST root.
Slack and Shopify seem to be affected.
From my understanding, the only way to remedy is to move away from Lets Encrypt...
Please correct me if I am wrong.