Help thread for DST Root CA X3 expiration (September 2021)

There are some details on how OpenSSL will break when DST Root X3 expires if a server is sending the default chain in this thread:

And a questions for it thread, though it looks like it's since been closed:

I haven't heard of any specific vendor having backported a fix for it to older OpenSSL, but that doesn't mean it hasn't happened.

If your OpenSSL 1.0.x-based system is only connecting to servers you control, and those servers don't need to maintain compatibility with old Android, then you probably want your servers to be using the "alternate" chain that doesn't include the expiring DST Root.

9 Likes