# Fixing Windows installs that don't receive updates to their trusted roots

**URL:** https://community.letsencrypt.org/t/fixing-windows-installs-that-dont-receive-updates-to-their-trusted-roots/161162
**Category:** Help
**Created:** [September 30, 2021, 9:32pm UTC](https://community.letsencrypt.org/t/fixing-windows-installs-that-dont-receive-updates-to-their-trusted-roots/161162 "2021-09-30T21:32:42Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![Cryptoman](https://avatars.discourse-cdn.com/v4/letter/c/439d5e/32.png) [@Cryptoman](https://community.letsencrypt.org/u/Cryptoman)
#### Post date: [September 30, 2021, 10:01pm UTC](https://community.letsencrypt.org/t/fixing-windows-installs-that-dont-receive-updates-to-their-trusted-roots/161162/3 "2021-09-30T22:01:55Z")

</div>

Chrome should show the chain: Subscriber Certificate \<– R3 \<– ISRG Root X1 (Self-Signed), whether your server has a long or short chain. You shouldn't show the old DST Root CA X3 anyway, unless it can't find the ISRG Root X1 (Self-signed) certificate in the client store.

![image](https://global.discourse-cdn.com/letsencrypt/original/3X/4/c/4c47fa4680f5cd1f05a34f6a707fd0f1a717b259.png)

On the Windows client, in a certificate management console, did you verify that the ISRG Root X1 certificate is present in the "Third Party Root Certification Authorities" directory?

---

_[View the full topic](https://community.letsencrypt.org/t/fixing-windows-installs-that-dont-receive-updates-to-their-trusted-roots/161162)._
