Help thread for DST Root CA X3 expiration (September 2021)

These are the two current chains:

  • Default chain: End-entity/leaf certificate (sig R3) ← R3 (sig ISRG Root X1) ← ISRG Root X1 (sig DST Root CA X3)

  • Alternate chain: End-entity/leaf certificate (sig R3) ← R3 (sig ISRG Root X1)

As you can see, neither R3 intermediate is signed by DST Root CA X3 and both chains include ISRG Root X1.


If you want the R3 intermediate signed by DST Root CA X3, you can download it here:

https://letsencrypt.org/certs/lets-encrypt-r3-cross-signed.pem

Pinning/installing that intermediate and using only your leaf certificate served by Let's Encrypt will work for now, but you should do whatever you can to try to move forward.

You can construct the old fullchain.pem by putting your new leaf certificate followed by the intermediate downloaded from the link above in a single file.

8 Likes