# Invalid intermediate certificate

**URL:** https://community.letsencrypt.org/t/invalid-intermediate-certificate/142712
**Category:** Help
**Created:** [January 14, 2021, 7:36am UTC](https://community.letsencrypt.org/t/invalid-intermediate-certificate/142712 "2021-01-14T07:36:40Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![pipa\_85](https://avatars.discourse-cdn.com/v4/letter/p/90db22/32.png) [@pipa\_85](https://community.letsencrypt.org/u/pipa_85)
#### Post date: [January 14, 2021, 7:36am UTC](https://community.letsencrypt.org/t/invalid-intermediate-certificate/142712/1 "2021-01-14T07:36:40Z")

</div>

Hello,  
Recently, we noticed that the certificate does not work correctly in some devices, the site [https://www.whynopadlock.com/](https://www.whynopadlock.com/) displays the following error:

**You have an invalid or missing intermediate (bundle) certificate. This may not break your padlock on all browsers, but will on others. Please contact your SSL Vendor for assistance with this error.**

It seems that the intermediate certificate of let's encrypt is no longer valid, I checked , it will expire in March 2021  
Please can you give me a valid let's encryp intermediate certificate?  
I thank you in advance. ![Intermediate_certificate_expire_date](https://global.discourse-cdn.com/letsencrypt/original/3X/1/2/121d872af9c021aa585c54338e6cfb984eb9488a.png)

 ![Invalid_intermediate_certificate](https://global.discourse-cdn.com/letsencrypt/original/3X/6/5/651e3c0fcec3ed4ef29125f037465b6057fe523d.png)

---

<div class="post-metadata">

### Author: ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)
#### Post date: [January 14, 2021, 8:01am UTC](https://community.letsencrypt.org/t/invalid-intermediate-certificate/142712/2 "2021-01-14T08:01:28Z")

</div>

Let's Encrypt recently updated its intermediate certificate from "Let's Encrypt Authority X3" to "R3".

If you use a well-behaved ACME client, it would have automatically started using the new intermediate at your last renewal. You shouldn't have noticed any difference.

In your case, perhaps you have been hardcoding the intermediate certificate. If that's the case, you'll need to use the new intermediate, which you can find on [https://letsencrypt.org/certificates](https://letsencrypt.org/certificates) : [https://letsencrypt.org/certs/lets-encrypt-r3-cross-signed.pem](https://letsencrypt.org/certs/lets-encrypt-r3-cross-signed.pem)

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [January 14, 2021, 9:49am UTC](https://community.letsencrypt.org/t/invalid-intermediate-certificate/142712/3 "2021-01-14T09:49:49Z")

</div>

> [@\_az](#):
>
> In your case, perhaps you have been hardcoding the intermediate certificate. If that's the case, you'll need to use the new intermediate (…)

Rather than hardcoding the current intermediate, I would like to advise to _fix the ACME client_/setup to **not hardcode** the intermediate at all.

---

<div class="post-metadata">

### Author: ![pipa\_85](https://avatars.discourse-cdn.com/v4/letter/p/90db22/32.png) [@pipa\_85](https://community.letsencrypt.org/u/pipa_85)
#### Post date: [January 15, 2021, 7:03pm UTC](https://community.letsencrypt.org/t/invalid-intermediate-certificate/142712/4 "2021-01-15T19:03:14Z")

</div>

Thank you very much it works with the new intermediate certificate. In our case, we import our certificates (the certificate issued by lest's encrypt and the intermediate certificate) into FortiWeb, so I downloaded the new intermediate certificate by following the link you gave me, then I imported it into Fortiweb.

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [January 15, 2021, 7:34pm UTC](https://community.letsencrypt.org/t/invalid-intermediate-certificate/142712/5 "2021-01-15T19:34:57Z")

</div>

> [@pipa\_85](#):
>
> I downloaded the new intermediate certificate by following the link you gave me, then I imported it into Fortiweb.

As stated, this might not be a future-proof "fix". It's more of a temporary workaround waiting for the same issue to come up one day.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [February 14, 2021, 7:35pm UTC](https://community.letsencrypt.org/t/invalid-intermediate-certificate/142712/6 "2021-02-14T19:35:03Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
