I see the certificate when using openssl s_client -connect bbqfield.com:443
but you're not sending the intermediate certificate(s). This makes sense, as the intermediate cert(s) (chain.pem
) and also the full chain (fullchain.pem
, which is just cert.pem
and chain.pem
concatenated into a single file) were also deleted by the script.
You can download the intermediate certificate(s) from Chain of Trust - Let's Encrypt
Please see Production Chain Changes for more info about the currently active certificate chain. This currently is "R3" and "ISRG Root X1" where the latter has been signed by "DST Root CA X3". So your chain.pem
would consist of the R3 intermediate signed by ISRG Root X1 and the ISRG Root X1 certificate signed by "DST Root CA X3". All these files are availalbe from the Chain of Trust page I linked above, also as PEM files you can use directly on your server.