4 ms·
You should contact Heroku, to ask them to stop sending that 3rd DST_Root_CA_X3 certificate in the chain. And if you have only a few Heroku apps, you can fix tem
by gboudreau 5y ago
You should contact Heroku, to ask them to stop sending that 3rd DST_Root_CA_X3 certificate in the chain.
And if you have only a few Heroku apps, you can fix temporarily by obtaining a Let's Encrypt certificate another way, and upload it on Heroku (their web dashboard allows you to do that).
I myself changed the DNS entry temporarily, got myself a LE cert on another server, and then changed back the DNS to point to Heroku. I then uploaded me cert chain (two certificates; mine and the R3); and the private key, using the Heroku dashboard.
Heroku now has 90 days to fix their side, and then I will be able to switch back to using ACM.