Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: nummer378.de
I ran this command: openssl s_client -connect nummer378.de:443 -showcerts
It produced this output:
CONNECTED(000001A4)
depth=1 CN = R3, O = Let's Encrypt, C = US
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN = nummer378.de
verify return:1
---
Certificate chain
0 s:CN = nummer378.de
i:CN = R3, O = Let's Encrypt, C = US
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Apr 1 08:17:16 2023 GMT; NotAfter: Jun 30 08:17:15 2023 GMT
-----BEGIN CERTIFICATE-----
MIIEFjCCAv6gAwIBAgIPPSBhcHJpbCBmb29scyA9MA0GCSqGSIb3DQEBCwUAMDIx
CzAJBgNVBAMMAlIzMRYwFAYDVQQKDA1MZXQncyBFbmNyeXB0MQswCQYDVQQGDAJV
UzAeFw0yMzA0MDEwODE3MTZaFw0yMzA2MzAwODE3MTVaMBcxFTATBgNVBAMMDG51
bW1lcjM3OC5kZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALk8AakO
VA7/IbFs3mVemtoNSZIXQZqgNocTdxy7rprycwm3K9zhVfkryRSPHwBYS8sO6lFy
+j0epla3TKMkeqke4uUP1V4nXPvnVOecNKY4edHUQtgvSCn00Nmi5jp46pkzSg+l
BGuIEQAPVhx27XwrvHZssiX8FBwuK0XZ9x/QPTtja61Gutn3ekjJYEaWEqOcHbCv
HzF6oKR0rqnaEAi34cDDJvHnzyEXw9KRAncHn04h3Hy9kvXE5AV6LTHxhXVo+Tu9
PQG73aGQ2p/9DQ3+hlnCZjuU2LkwUnkTO0KhvNdrXwoEgw3KGwYq+MopDYBjegCV
Ph5GjeeVa5AFSLUCAwEAAaOCAUIwggE+MB8GA1UdIwQYMBaAFJrBA/R7ycax/9RD
QZf0IrryWO5dMBcGA1UdEQQQMA6CDG51bW1lcjM3OC5kZTAOBgNVHQ8BAf8EBAMC
BaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTR+pAL
yNZCLsPPnmWVVWdKIsWVbTAPBgNVHRMBAf8EBTADAQEAMEwGA1UdIARFMEMwCAYG
Z4EMAQIBMDcGCysGAQQBgt8TAQEBMCgwJgYIKwYBBQUHAgEWGmh0dHA6Ly9jcHMu
bGV0c2VuY3J5cHQub3JnMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYVaHR0
cDovL3IzLm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5sZW5j
ci5vcmcvMA0GCSqGSIb3DQEBCwUAA4IBAQDGYuJic9jsWKjFZSban1yU3L85jbv/
VsX9aWPE3aPIWhoI1hFF73dJN2oOeoy2mGmpjbO4e2a1OGZzXxIaMZt74df7fOtf
L59dTj64bM2j7HS4dDx/dHnDDMQITD99oF398enemqfk1UZwDr2QwtlCHU015JE4
f6s9dHA+/jemIl29WtxsVgCQTbN0FqZijiYvfZpt73p6e4bCr7V+GOG/UDkX/07/
rBxH1pC6Zm5Zf3ufNjBgu4LueV+/4w5Rv2q/do8zahuHxw/da5/33D0DVZNFSHQl
4PiB2IdIRm9xdVqFa8gUUAs/Ui5kdWVDHzN7q3Tr3E5l50V7VHMxfwNZ
-----END CERTIFICATE-----
1 s:CN = R3, O = Let's Encrypt, C = US
i:CN = ISRG Root X1, O = Internet Security Research Group, C = US
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Sep 4 00:00:00 2020 GMT; NotAfter: Sep 15 16:00:00 2025 GMT
-----BEGIN CERTIFICATE-----
MIIEkzCCAnugAwIBAgIRANMJopTmTVe5XsmXtIRP9ZswDQYJKoZIhvcNAQELBQAw
TzEVMBMGA1UEAwwMSVNSRyBSb290IFgxMSkwJwYDVQQKDCBJbnRlcm5ldCBTZWN1
cml0eSBSZXNlYXJjaCBHcm91cDELMAkGA1UEBgwCVVMwHhcNMjAwOTA0MDAwMDAw
WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQDDAJSMzEWMBQGA1UECgwNTGV0J3Mg
RW5jcnlwdDELMAkGA1UEBgwCVVMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDvRvtY92Mpr9fO4TMw/hi+Hn2cU6/cGiwSw1idc7pYpNtgo2QyFtaTi5vr
iAmMJ1lVMQIimYGtaM6qgR1I+j8qLgQLFAwo4hs4IqL9luFIbSQqIMfuFn4gJ9ks
0MDL66i36jQ5NPtLmtYAOzP52g3dpab6N67dyKLbur9YhFCsKGM2c3GWspMl34V3
H/rdtQOUIXUhIWBrXnDnYk2OEukO6fQPdap5DJRMJFUmhGGBf2JuoAqjhfnB8XsQ
msoKlml8Jlz5LWNLcnYQ1pJUf6AFqYV/5NBEUlo3KIX1xqfzYBJU0kjUfGnOgSCd
R2G5dGaPcVWRMFJM0PSHaDTcuSv1AgMBAAGjgYYwgYMwHwYDVR0jBBgwFoAUtBgU
m9frFhmbIJV0icg72wBqviwwDgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsG
AQUFBwMCBggrBgEFBQcDATAdBgNVHQ4EFgQUmsED9HvJxrH/1ENBl/QiuvJY7l0w
EgYDVR0TAQH/BAgwBgEB/wIBADANBgkqhkiG9w0BAQsFAAOCAgEAV/AJt3f5JN1C
nNcXH9aTuv2C+WJZa7/d9QxIePdiNP/KB3QFQ5aWKunENijqZ9akji76gx7QTH/+
5GOaG1+je2tGULj/22wEcoYpzC9Ny+dDGrzljzK2dfbnK825TG+0O25t4NEfg2yl
ewUbJwJm8EoI+1eOfMlQUD1WXoAQujLJx0KSNslRiMyz41rH0ZI59NlU51wqEiF6
5siInOciHSoXk0yWybSwD71RWK4Lw+B2HleB3jKGbEW/xoHegrJvZjabbKYljIyl
94cN3HSU1m164i8YCpyE6ZHrClIH9618pJRAstapllHD92FbD6Rns/5mSbTHrSzq
D5iQKCuNpu9eKN5s/eN06CJ9BX7n/WF1Up9BZ73sLJcvjkRWcAq9BqzFttKiNnyk
5MB4PSe4hbDqUc12fq4xdt6vG/FKLKuoHKdQnMn7Yg6GY3QTbgBepqBQFapkly/o
cFXto11agbtmkBP7pWO5nvNEocYQJ2IHldEorMD1SgRvN5xvbvDPCjZDued2vtaW
mdXNYrdecmQi2IKPX8xLl83RbCLDdXDHT8T69OtuFDVV96dBxd96i86Gqo1yuETl
FU+ydp8tFBUMAVi2UwSXO4zLrzX/u5oKWr9OQ6DeoEvHr7W2klgz1I77R9CeLgk6
U4NkxNzL/jskdQ8D7CC1+3eN4y+zURI=
-----END CERTIFICATE-----
---
Server certificate
subject=CN = nummer378.de
issuer=CN = R3, O = Let's Encrypt, C = US
---
My web server is (include version): CERN httpd. Don't know about the version, haven't updated in a while.
The operating system my web server runs on is (include version): Debian Lenny
My hosting provider, if applicable, is: Hetzner
I can login to a root shell on my machine (yes or no, or I don't know): Only during working hours
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot): I don't use a client for security reasons. I use curl.
So, I updated my certificates last night - manually like I always do, because I hate automation - and now it's broken on all clients!!! I tried like everything and it doesn't work!
- With Firefox I get
SEC_ERROR_UNKNOWN_ISSUER
- Chrome says
NET::ERR_CERT_AUTHORITY_INVALID
- OpenSSL reports
unable to get local issuer certificate
- Windows (schannel) errors with
SEC_E_UNTRUSTED_ROOT
I do believe I have ISRG Root X1 installed, at least this used to work??? This domain has been running fine for years, but now I get this error on all of my machines?
The certificate looks fine, so I don't know what the problem is:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
3d:20:61:70:72:69:6c:20:66:6f:6f:6c:73:20:3d
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN = R3, O = Let's Encrypt, C = US
Validity
Not Before: Apr 1 08:17:16 2023 GMT
Not After : Jun 30 08:17:15 2023 GMT
Subject: CN = nummer378.de
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b9:3c:01:a9:0e:54:0e:ff:21:b1:6c:de:65:5e:
9a:da:0d:49:92:17:41:9a:a0:36:87:13:77:1c:bb:
ae:9a:f2:73:09:b7:2b:dc:e1:55:f9:2b:c9:14:8f:
1f:00:58:4b:cb:0e:ea:51:72:fa:3d:1e:a6:56:b7:
4c:a3:24:7a:a9:1e:e2:e5:0f:d5:5e:27:5c:fb:e7:
54:e7:9c:34:a6:38:79:d1:d4:42:d8:2f:48:29:f4:
d0:d9:a2:e6:3a:78:ea:99:33:4a:0f:a5:04:6b:88:
11:00:0f:56:1c:76:ed:7c:2b:bc:76:6c:b2:25:fc:
14:1c:2e:2b:45:d9:f7:1f:d0:3d:3b:63:6b:ad:46:
ba:d9:f7:7a:48:c9:60:46:96:12:a3:9c:1d:b0:af:
1f:31:7a:a0:a4:74:ae:a9:da:10:08:b7:e1:c0:c3:
26:f1:e7:cf:21:17:c3:d2:91:02:77:07:9f:4e:21:
dc:7c:bd:92:f5:c4:e4:05:7a:2d:31:f1:85:75:68:
f9:3b:bd:3d:01:bb:dd:a1:90:da:9f:fd:0d:0d:fe:
86:59:c2:66:3b:94:d8:b9:30:52:79:13:3b:42:a1:
bc:d7:6b:5f:0a:04:83:0d:ca:1b:06:2a:f8:ca:29:
0d:80:63:7a:00:95:3e:1e:46:8d:e7:95:6b:90:05:
48:b5
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
9A:C1:03:F4:7B:C9:C6:B1:FF:D4:43:41:97:F4:22:BA:F2:58:EE:5D
X509v3 Subject Alternative Name:
DNS:nummer378.de
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Subject Key Identifier:
D1:FA:90:0B:C8:D6:42:2E:C3:CF:9E:65:95:55:67:4A:22:C5:95:6D
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Policy: 1.3.6.1.4.1.44947.1.1.1
CPS: http://cps.letsencrypt.org
Authority Information Access:
OCSP - URI:http://r3.o.lencr.org
CA Issuers - URI:http://r3.i.lencr.org/
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
c6:62:e2:62:73:d8:ec:58:a8:c5:65:26:da:9f:5c:94:dc:bf:
39:8d:bb:ff:56:c5:fd:69:63:c4:dd:a3:c8:5a:1a:08:d6:11:
45:ef:77:49:37:6a:0e:7a:8c:b6:98:69:a9:8d:b3:b8:7b:66:
b5:38:66:73:5f:12:1a:31:9b:7b:e1:d7:fb:7c:eb:5f:2f:9f:
5d:4e:3e:b8:6c:cd:a3:ec:74:b8:74:3c:7f:74:79:c3:0c:c4:
08:4c:3f:7d:a0:5d:fd:f1:e9:de:9a:a7:e4:d5:46:70:0e:bd:
90:c2:d9:42:1d:4d:35:e4:91:38:7f:ab:3d:74:70:3e:fe:37:
a6:22:5d:bd:5a:dc:6c:56:00:90:4d:b3:74:16:a6:62:8e:26:
2f:7d:9a:6d:ef:7a:7a:7b:86:c2:af:b5:7e:18:e1:bf:50:39:
17:ff:4e:ff:ac:1c:47:d6:90:ba:66:6e:59:7f:7b:9f:36:30:
60:bb:82:ee:79:5f:bf:e3:0e:51:bf:6a:bf:76:8f:33:6a:1b:
87:c7:0f:dd:6b:9f:f7:dc:3d:03:55:93:45:48:74:25:e0:f8:
81:d8:87:48:46:6f:71:75:5a:85:6b:c8:14:50:0b:3f:52:2e:
64:75:65:43:1f:33:7b:ab:74:eb:dc:4e:65:e7:45:7b:54:73:
31:7f:03:59
Maybe there's something broken on LE side? Can someone check?