# Fixing Windows installs that don't receive updates to their trusted roots

**URL:** https://community.letsencrypt.org/t/fixing-windows-installs-that-dont-receive-updates-to-their-trusted-roots/161162
**Category:** Help
**Created:** [September 30, 2021, 9:32pm UTC](https://community.letsencrypt.org/t/fixing-windows-installs-that-dont-receive-updates-to-their-trusted-roots/161162 "2021-09-30T21:32:42Z")
**Posts on this page:** 1
**Showing post:** 17

<div class="post-metadata">

### Author: ![danny2014](https://avatars.discourse-cdn.com/v4/letter/d/f0a364/32.png) [@danny2014](https://community.letsencrypt.org/u/danny2014)
#### Post date: [September 30, 2021, 10:39pm UTC](https://community.letsencrypt.org/t/fixing-windows-installs-that-dont-receive-updates-to-their-trusted-roots/161162/17 "2021-09-30T22:39:17Z")

</div>

Oof, finally solved the problem.  
If you export the ISRG Root X1 certificate from a working Windows 10 computer and import it from a non-working computer, the import won't work.  
I downloaded the self-signed ISRG Root X1 .der file from [Chain of Trust - Let's Encrypt](https://letsencrypt.org/certificates/) and imported it and voila, it was able to access all sites with letsencrypt certificate without errors.  
So my solution for Windows client machines would be to delete DST Root CA X3 certificate, download and import ISRG Root X1 certificate.  
I still don't understand why this particular client wasn't served the new certificate from the server though.

---

_[View the full topic](https://community.letsencrypt.org/t/fixing-windows-installs-that-dont-receive-updates-to-their-trusted-roots/161162)._
