# Help thread with cremationlab

**URL:** <https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578>\
**Category:** Help\
**Created:** [October 1, 2021, 6:03am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578 "2021-10-01T06:03:04Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![cremationlab](https://avatars.discourse-cdn.com/v4/letter/c/b19c9b/32.png) [@cremationlab](https://community.letsencrypt.org/u/cremationlab)\
**Post date:** [October 1, 2021, 6:03am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/1 "2021-10-01T06:03:04Z")

</div>

Where do I get the DST\_Root\_CA\_X3.pem file?

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [October 1, 2021, 8:46pm UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/2 "2021-10-01T20:46:10Z")

</div>

10 posts were split to a new topic: [AWS with CentOS - tweaking configs](https://community.letsencrypt.org/t/aws-with-centos-tweaking-configs/161580)

---

<div class="post-metadata">

**Author:** ![punchi](https://avatars.discourse-cdn.com/v4/letter/p/8baadc/32.png) [@punchi](https://community.letsencrypt.org/u/punchi)\
**Post date:** [October 1, 2021, 2:16am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/10 "2021-10-01T02:16:05Z")

</div>

> [@AWS with CentOS - tweaking configs](https://community.letsencrypt.org/t/aws-with-centos-tweaking-configs/161580/3):
>
> `openssl s_client -connect EXAMPLE.org:443 -servername EXAMPLE.org`

The only trustworthy !

---

<div class="post-metadata">

**Author:** ![punchi](https://avatars.discourse-cdn.com/v4/letter/p/8baadc/32.png) [@punchi](https://community.letsencrypt.org/u/punchi)\
**Post date:** [October 1, 2021, 2:29am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/11 "2021-10-01T02:29:58Z")

</div>

Hi @jsha ! almost a beta tester 😅

Site: [app.gesnex.com](http://app.gesnex.com)  
OS: Amazon Linux AMI 2018.03  
OpenSSL 1.0.2k-fips 26 Jan 2017

The another site [www.gesnex.com](http://www.gesnex.com) is working fine, however under Amazon Linux 2 this solution worked fine: [RHEL/CentOS 7 Fix for Let’s Encrypt Change | by Dorai Ashok S A | Sep, 2021 | Dev Genius](https://blog.devgenius.io/rhel-centos-7-fix-for-lets-encrypt-change-8af2de587fe4) ( trust dump --filter.... )

But with this one ([app.gesnex.com](http://app.gesnex.com)), I blacklisted the cert ( /etc/pki/ca-trust/source/blacklist/DST-Root-CA-X3.pem ), updated with `update-ca-trust` but the command `openssl s_client -connect app.gesnex.com:443 -servername gesnex.com` still saying `Verify return code: 10 (certificate has expired)`. The command `trust` do not exists.

it worked for @frsp1 to erase the cert editing the file, but when you block it (blacklist), I shouldn't be considered, it should not be necessary to remove it from the .pem/.crt files IMHO

Any ideas? 😬

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2021, 2:51am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/12 "2021-10-01T02:51:08Z")

</div>

> [@punchi](#):
>
> openssl s\_client -connect [app.gesnex.com:443](http://app.gesnex.com:443) -servername [gesnex.com](http://gesnex.com)

That works for me:  
[even with the matching servername]

```nohighlight
openssl version
OpenSSL 1.1.1 11 Sep 2018
openssl s_client -connect app.gesnex.com:443 -servername gesnex.com
CONNECTED(00000005)
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = R3
verify return:1
depth=0 CN = app.gesnex.com
verify return:1
---
Certificate chain
 0 s:CN = app.gesnex.com
   i:C = US, O = Let's Encrypt, CN = R3
 1 s:C = US, O = Let's Encrypt, CN = R3
   i:C = US, O = Internet Security Research Group, CN = ISRG Root X1
 2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1
   i:O = Digital Signature Trust Co., CN = DST Root CA X3
---

```

But it fails with:

```nohighlight
openssl version
OpenSSL 1.0.1f 6 Jan 2014
openssl s_client -connect app.gesnex.com:443 -servername gesnex.com
CONNECTED(00000003)
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1
verify error:num=20:unable to get local issuer certificate
verify return:0
---
Certificate chain
 0 s:/CN=app.gesnex.com
   i:/C=US/O=Let's Encrypt/CN=R3
 1 s:/C=US/O=Let's Encrypt/CN=R3
   i:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
 2 s:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
   i:/O=Digital Signature Trust Co./CN=DST Root CA X3
---

```

**Which version of OpenSSL are you using?**

---

<div class="post-metadata">

**Author:** ![frsp1](https://avatars.discourse-cdn.com/v4/letter/f/a8b319/32.png) [@frsp1](https://community.letsencrypt.org/u/frsp1)\
**Post date:** [October 1, 2021, 5:59am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/13 "2021-10-01T05:59:17Z")

</div>

Yeah, you've got to get rid of your upper-level CA (X3). Here is the relevant info I get when I run:

```nohighlight
openssl s_client -showcerts -connect app.gesnex.com:443 

```

```nohighlight
CONNECTED(00000005)
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
---
Certificate chain
 0 s:/CN=app.gesnex.com
   i:/C=US/O=Let's Encrypt/CN=R3
-----BEGIN CERTIFICATE-----
MIIFQzCCBCugAwIBAgISBDMle2WKcts3tHOLEh//xmEMMA0GCSqGSIb3DQEBCwUA

```

Just to be clear, are you using acme or certbot?  
Have you already done the CA blacklist as per my original post?  
Does your cert (or chain) include the X3 CA?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2021, 6:14am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/14 "2021-10-01T06:14:56Z")

</div>

@cremationlab  
I can't find it online now, but here it is:

```nohighlight
-----BEGIN CERTIFICATE-----
MIIDSjCCAjKgAwIBAgIQRK+wgNajJ7qJMDmGLvhAazANBgkqhkiG9w0BAQUFADA/
MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT
DkRTVCBSb290IENBIFgzMB4XDTAwMDkzMDIxMTIxOVoXDTIxMDkzMDE0MDExNVow
PzEkMCIGA1UEChMbRGlnaXRhbCBTaWduYXR1cmUgVHJ1c3QgQ28uMRcwFQYDVQQD
Ew5EU1QgUm9vdCBDQSBYMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB
AN+v6ZdQCINXtMxiZfaQguzH0yxrMMpb7NnDfcdAwRgUi+DoM3ZJKuM/IUmTrE4O
rz5Iy2Xu/NMhD2XSKtkyj4zl93ewEnu1lcCJo6m67XMuegwGMoOifooUMM0RoOEq
OLl5CjH9UL2AZd+3UWODyOKIYepLYYHsUmu5ouJLGiifSKOeDNoJjj4XLh7dIN9b
xiqKqy69cK3FCxolkHRyxXtqqzTWMIn/5WgTe1QLyNau7Fqckh49ZLOMxt+/yUFw
7BZy1SbsOFU5Q9D8/RhcQPGX69Wam40dutolucbY38EVAjqr2m7xPi71XAicPNaD
aeQQmxkqtilX4+U9m5/wAl0CAwEAAaNCMEAwDwYDVR0TAQH/BAUwAwEB/zAOBgNV
HQ8BAf8EBAMCAQYwHQYDVR0OBBYEFMSnsaR7LHH62+FLkHX/xBVghYkQMA0GCSqG
SIb3DQEBBQUAA4IBAQCjGiybFwBcqR7uKGY3Or+Dxz9LwwmglSBd49lZRNI+DT69
ikugdB/OEIKcdBodfpga3csTS7MgROSR6cz8faXbauX+5v3gTt23ADq1cEmv8uXr
AvHRAosZy5Q6XkjEGB5YGV8eAlrwDPGxrancWYaLbumR9YbK+rlmM6pZW87ipxZz
R8srzJmwN0jP41ZL9c8PDHIyh8bwRLtTcm1D9SZImlJnt1ir/md2cXjbDaJWFBM5
JDGFoqgCWjBH4d1QB7wCCZAA62RjYJsWvIjJEubSfZGL+T0yjWW06XyxV3bqxbYo
Ob8VZRzI9neWagqNdwvYkQsEjgfbKbYK7p2CNTUQ
-----END CERTIFICATE-----

```

---

<div class="post-metadata">

**Author:** ![cremationlab](https://avatars.discourse-cdn.com/v4/letter/c/b19c9b/32.png) [@cremationlab](https://community.letsencrypt.org/u/cremationlab)\
**Post date:** [October 1, 2021, 6:17am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/15 "2021-10-01T06:17:09Z")

</div>

So I copy that into the path above and run that command, and will point me to the new root cert?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2021, 6:17am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/16 "2021-10-01T06:17:28Z")

</div>

Or get it from here:  
[crt.sh | 8395](https://crt.sh/?id=8395)

Which command above?

---

<div class="post-metadata">

**Author:** ![cremationlab](https://avatars.discourse-cdn.com/v4/letter/c/b19c9b/32.png) [@cremationlab](https://community.letsencrypt.org/u/cremationlab)\
**Post date:** [October 1, 2021, 6:27am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/17 "2021-10-01T06:27:39Z")

</div>

Where is my chain.pem file in centos and what would I delete?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2021, 6:32am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/18 "2021-10-01T06:32:36Z")

</div>

I'm not sure I understand what you mean or want.  
Which guide/instruction/post are you trying to follow?

---

<div class="post-metadata">

**Author:** ![cremationlab](https://avatars.discourse-cdn.com/v4/letter/c/b19c9b/32.png) [@cremationlab](https://community.letsencrypt.org/u/cremationlab)\
**Post date:** [October 1, 2021, 6:33am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/19 "2021-10-01T06:33:09Z")

</div>

Putting the pem file in the blacklist folder and running the update command

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2021, 6:34am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/20 "2021-10-01T06:34:43Z")

</div>

I'm truly sorry.  
I must have looked at 1000 posts today...  
Can you be a bit more specific?

---

<div class="post-metadata">

**Author:** ![cremationlab](https://avatars.discourse-cdn.com/v4/letter/c/b19c9b/32.png) [@cremationlab](https://community.letsencrypt.org/u/cremationlab)\
**Post date:** [October 1, 2021, 6:36am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/21 "2021-10-01T06:36:07Z")

</div>

[https://community.letsencrypt.org/t/fixing-validation-from-centos-instances/161182?u=cremationlab](https://community.letsencrypt.org/t/fixing-validation-from-centos-instances/161182)

This thread is too damn convoluted

---

<div class="post-metadata">

**Author:** ![cremationlab](https://avatars.discourse-cdn.com/v4/letter/c/b19c9b/32.png) [@cremationlab](https://community.letsencrypt.org/u/cremationlab)\
**Post date:** [October 1, 2021, 6:36am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/22 "2021-10-01T06:36:38Z")

</div>

It says to remove the X3 mention from the chain.pem file

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2021, 6:37am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/23 "2021-10-01T06:37:36Z")

</div>

> [@cremationlab](#):
>
> Where is my chain.pem

That depends on the ACME client used.  
`certbot` saves it at:  
`/etc/letsencrypt/live/EXMAPLE.COM/chain.pem`  
`acme.sh` saves it at:  
`/roor/.acme.sh/EXAMPLE.COM/ca.cer`

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2021, 6:38am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/24 "2021-10-01T06:38:35Z")

</div>

> [@cremationlab](#):
>
> It says to remove the X3 mention from the chain.pem file

Where is this IT you speak of?  
Again there were +1000 posts here today.

---

<div class="post-metadata">

**Author:** ![cremationlab](https://avatars.discourse-cdn.com/v4/letter/c/b19c9b/32.png) [@cremationlab](https://community.letsencrypt.org/u/cremationlab)\
**Post date:** [October 1, 2021, 6:40am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/25 "2021-10-01T06:40:37Z")

</div>

[https://community.letsencrypt.org/t/fixing-validation-from-centos-instances/161182](https://community.letsencrypt.org/t/fixing-validation-from-centos-instances/161182)

Post by fsrp1

My server doesnt have /etc/letsencrypt or /root/.acme.sh

It uses Plesk if that matters

---

<div class="post-metadata">

**Author:** ![cremationlab](https://avatars.discourse-cdn.com/v4/letter/c/b19c9b/32.png) [@cremationlab](https://community.letsencrypt.org/u/cremationlab)\
**Post date:** [October 1, 2021, 6:43am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/26 "2021-10-01T06:43:35Z")

</div>

Looks like they are in /usr/local/psa/var/modules/letsencrypt

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2021, 6:43am UTC](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578/27 "2021-10-01T06:43:50Z")

</div>

Well it should have a web server... which one is that?

[Next page](https://community.letsencrypt.org/t/help-thread-with-cremationlab/161578.md?page=2)
