2 ms·
Oof, felt this pain. We are having to blacklist the expired SSL cert because our openssl version prefer it over the valid cert. Time to redeploy all things.
by mego22 5y ago
Oof, felt this pain. We are having to blacklist the expired SSL cert because our openssl version prefer it over the valid cert. Time to redeploy all things.
- pa9am 5y agoThis also bit me. I thought I was in the clear not using anything with outdated CA keystores. Turns out that some TLS implementations don't trust the connection if the server provides an expired CA in the certificate chain. This includes the Nextcloud client for Windows and the DNS over TLS implementation in Android 11. Adding the argument --preferred-chain "ISRG Root X1" to certbot fixes this by not chaining the expired CA X3...