# Help thread for DST Root CA X3 expiration (September 2021)

**URL:** https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190
**Category:** Help
**Created:** [April 6, 2021, 11:43pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190 "2021-04-06T23:43:50Z")
**Posts on this page:** 20
**Page:** 31

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [October 8, 2021, 11:42am UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1252 "2021-10-08T11:42:35Z")

</div>

6 posts were split to a new topic: [iOS and Android issue](https://community.letsencrypt.org/t/ios-and-android-issue/162584)

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [October 8, 2021, 11:45am UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1253 "2021-10-08T11:45:17Z")

</div>

@kmconklin  
That is the correct way to use that parameter:

> [@kmconklin](#):
>
> `sudo certbot --preferred-chain "ISRG Root X1"`

But, it requires having `certbot` v1.12.0(or higher)  
Which `certbot` version are you using?  
`certbot --version`

---

<div class="post-metadata">

### Author: ![mkrtchyanartur](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mkrtchyanartur/32/54549_2.png) [@mkrtchyanartur](https://community.letsencrypt.org/u/mkrtchyanartur)
#### Post date: [October 11, 2021, 6:27pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1254 "2021-10-11T18:27:36Z")

</div>

Am I right assuming that renewal of the certificates will not solve the issue ? We have some clients who still have a chain pointing to expired certificate. Other than them updating their OS and/or browsers is there anything I can do as service provider ?

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [October 11, 2021, 7:00pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1255 "2021-10-11T19:00:43Z")

</div>

> [@mkrtchyanartur](#):
>
> Am I right assuming that renewal of the certificates will not solve the issue ?

Correct, usually the end leaf certificate is perfectly fine and valid. However, with some ACME clients, if the server operator would want to use the "short" certificate chain, the only way to force the client to retreive the short chain from the ACME server is to force a renewal in combination with "get me the short chain" option for the ACME client (with certbot you'd use `--preferred-chain "ISRG Root X1"`).

---

<div class="post-metadata">

### Author: ![mkrtchyanartur](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mkrtchyanartur/32/54549_2.png) [@mkrtchyanartur](https://community.letsencrypt.org/u/mkrtchyanartur)
#### Post date: [October 11, 2021, 7:17pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1256 "2021-10-11T19:17:20Z")

</div>

@Osiris thanks a lot for clarifying, I'm using auto-ssl/lua-resty-auto-ssl with resty to generate certificate for few hundred websites and I think it uses dehydrated under the hood which supports preferred-chain option. However it's a big hassle to generate few hundred certificates. Also what's interesting when I check the chain on my machine I get short version but for the same certificate the clients who have issues get longer chain, that's why I'm not sure if regenerating will solve it at all?

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [October 11, 2021, 7:20pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1257 "2021-10-11T19:20:31Z")

</div>

> [@mkrtchyanartur](#):
>
> Also what's interesting when I check the chain on my machine I get short version but for the same certificate the clients who have issues get longer chain

If you're "checking the chain" using a browser, then note that this is not a good way to check which chain your server is sending. It only shows one of the possible chains a browser can make. And browsers often can make a few different chains. It's better to use `openssl s_client -connect $hostname:443 -servername $hostname` or online checkers such as [SSL Checker](https://www.sslshopper.com/ssl-checker.html) .

Also note that if you choose to use the short chain and the actual issue your clients have is a lack of ISRG Root X1 in their certificate root store, the short chain won't fix anything.

---

<div class="post-metadata">

### Author: ![mkrtchyanartur](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mkrtchyanartur/32/54549_2.png) [@mkrtchyanartur](https://community.letsencrypt.org/u/mkrtchyanartur)
#### Post date: [October 11, 2021, 7:25pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1258 "2021-10-11T19:25:12Z")

</div>

Thanks @Osiris the issue with client is that her browser shows ISRG Root X1 -\> DST Root CA X3 and the last one being expired. Would this mean then I can then regenerate with short chain this one and then it will be just fine ? What I'm afraid of is that in her browser ISRG Root X1 might still point to expired one.

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [October 11, 2021, 7:28pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1259 "2021-10-11T19:28:39Z")

</div>

> [@mkrtchyanartur](#):
>
> Would this mean then I can then regenerate with short chain this one and then it will be just fine ? What I'm afraid of is that in her browser ISRG Root X1 might still point to expired one.

I think the thing you should be afraid of is that with the short chain your client would get an "issuer unknown" error. It looks like your client doesn't have ISRG Root X1 in the root store. I've seen more issues with Windows 7 not updating the root certificate store. Take a look around on the Community. I'm not a Windows 7 user, so I have no clue about it, but it did came up a few times.

---

<div class="post-metadata">

### Author: ![mkrtchyanartur](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mkrtchyanartur/32/54549_2.png) [@mkrtchyanartur](https://community.letsencrypt.org/u/mkrtchyanartur)
#### Post date: [October 11, 2021, 7:49pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1260 "2021-10-11T19:49:58Z")

</div>

So the safest path is to ask them to update their OS ?

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [October 11, 2021, 8:18pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1261 "2021-10-11T20:18:48Z")

</div>

I think their Windows 7 is missing the ISRG Root X1 indeed due to missing updates. See for example the following post from a different thread with a possible solution: [Windows 7 Chrome - NET::ERR\_CERT\_DATE\_INVALID - #48 by i4004](https://community.letsencrypt.org/t/windows-7-chrome-net-err-cert-date-invalid/161246/48)

---

<div class="post-metadata">

### Author: ![SanderMol](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@SanderMol](https://community.letsencrypt.org/u/SanderMol)
#### Post date: [October 12, 2021, 2:29pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1262 "2021-10-12T14:29:19Z")

</div>

Greetings LE community,

We have recently changed our certificates to use `--preferred-chain "ISRG Root X1` as we did not have control over clients connecting to our services. This worked perfectly. However, I was wondering what the difference in compatibility between the short-chain vs the default longer chain is.

Is it expected we migrate to the longer default chain eventually or is the shorter chain also long-lived supported?

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [October 12, 2021, 3:23pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1263 "2021-10-12T15:23:11Z")

</div>

Hi there Sander, welcome!

The longer chain is purely there for compatibility for Android older than 7.1.1.

The short chain is in principle the "correct" chain, but lacks older Android compatibility, so LE chose to use the longer chain by default.

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [October 12, 2021, 6:28pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1264 "2021-10-12T18:28:23Z")

</div>

> [@SanderMol](#):
>
> is the shorter chain also long-lived supported?

Both trust paths hinge on the same cert ("ISRG Root X1") - which only has one expiration date.  
So that makes the lifespan of both trust paths identical.

---

<div class="post-metadata">

### Author: ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)
#### Post date: [October 12, 2021, 6:35pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1265 "2021-10-12T18:35:53Z")

</div>

> [@rg305](#):
>
> Both trust paths hinge on the same cert ("ISRG Root X1") - which only has one expiration date.  
> So that makes the lifespan of both trust paths identical.

Just to clarify:

ISRG Root X1 cross signed certificate served in long chain will expire at Sep 30 18:14:03 2024 GMT

ISRG Root X1 self signed certificate will expire at Jun 4 11:04:38 2035 GMT

Cheers,  
sahsanu

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [October 12, 2021, 6:49pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1266 "2021-10-12T18:49:41Z")

</div>

> [@sahsanu](#):
>
> ISRG Root X1 cross signed certificate served in long chain will expire at Sep 30 18:14:03 2024 GMT

But that wouldn't hamper a non-Android-pre-7.1.1 client _even_ if the "long" chain was used by the server, as such clients would chain to the ISRG Root X1 in their trust store and would ignore the cross-signed ISRG Root X1 anyway. The expiry date of Sep 30 18:14:03 2024 GMT is just relevant for older Androids.

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [October 12, 2021, 6:53pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1267 "2021-10-12T18:53:53Z")

</div>

Point taken.  
YMMV; As their expiry dates are not seen equally by all clients.  
The ones that can "short-circuit" the validation, will use the longer date explicitly seen in their trust store.  
The ones that can't must rely on the validity of the signer (outside of the root itself).

---

<div class="post-metadata">

### Author: ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)
#### Post date: [October 12, 2021, 6:56pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1268 "2021-10-12T18:56:08Z")

</div>

Yes, correct. I just was trying to clarify this question:

> [@SanderMol](#):
>
> Is it expected we migrate to the longer default chain eventually or is the shorter chain also long-lived supported?

---

<div class="post-metadata">

### Author: ![mmncs](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@mmncs](https://community.letsencrypt.org/u/mmncs)
#### Post date: [October 12, 2021, 8:09pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1269 "2021-10-12T20:09:26Z")

</div>

Hi Let's Encrypt ,

I have followed the news about the expiration of X3 and I thought that I didn't have to do any changes for my website. But know I can see that my traffic has fallen by 20% and several browsers are not able to access the site without the big warning of an invalid certificate.

When I look at the chain it is as follows

DST Root CA X3

- ISRG Root X!  
- R3
  - [mydomain.com](http://mydomain.com)

and is says

This certificate is not valid (expired root)

> **[Beauton Art Gallery](https://www.beautonart.com)**
>
> Beauton Art Gallery is a Copenhagen based contemporary online art gallery with a strong collection of art from upcoming and renowned artists. Find the perfect original painting, drawing, art-photography or any other artwork from our high quality art...

Any help would be most appreciated.

Christian

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [October 12, 2021, 9:50pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1270 "2021-10-12T21:50:16Z")

</div>

Hi @mmncs and welcome to the LE community forum 🙂

I would try switching to the alternate/shorter trust path chain.  
How that is done on your server depends on may things...  
How much access do you have to it?  
Are you an admin or only make changes through a menu/panel?

---

<div class="post-metadata">

### Author: ![mmncs](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@mmncs](https://community.letsencrypt.org/u/mmncs)
#### Post date: [October 12, 2021, 9:55pm UTC](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190/1271 "2021-10-12T21:55:08Z")

</div>

Hi rg305,

I have full access and right now I am trying to upgrade my certbot to 1.12 where I have the command:

--preferred-chain "ISRG Root X1"

I have tried to add it to the letsencrypt conf file like this:

[renewalparams]  
authenticator = webroot  
rsa\_key\_size = 4096  
server = [https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)  
preferred\_chain = ISRG Root X1

[Previous page](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190.md?page=30)

[Next page](https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190.md?page=32)
