DST Root CA X3 issues with Traefik V1 and Consul in K8s

My domain is: develop.dis-apeer.com

My web server is (include version): Traefik 1.7.24

The operating system my web server runs on is (include version): Alpine Linux v3.9

I can login to a root shell on my machine (yes or no, or I don't know): no

So I am are running a Traefik V1 reverse proxy + Consul (for KV storage) from a stable Helm chart in a K8s cluster.
I am wondering is there any possibility to make Traefik not use "DST Root CA X3" as the trusted CA cert.
Anyone else using this tooling?

I am not sure how to apply this in the helm chart, but it is clear that traefik supports the option. The example stanza within the documentation is even the applicable chain name for your desired scenario:


Would be awesome if this would be possible in Traefik V1, but unfortunately this documentation refers to V2.


I believe you're going to have to wait for this issue to be closed ACME cannot select preferred chain in v1.7 which generates broken certificates (expired root CA in chain) · Issue #8480 · traefik/traefik · GitHub by this PR acme: add support of preferredchain in Traefik v1 by ldez · Pull Request #8482 · traefik/traefik · GitHub


