# Issues with Electron and expired root

**URL:** <https://community.letsencrypt.org/t/issues-with-electron-and-expired-root/160991>\
**Category:** Help\
**Created:** [September 30, 2021, 2:55pm UTC](https://community.letsencrypt.org/t/issues-with-electron-and-expired-root/160991 "2021-09-30T14:55:35Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)\
**Post date:** [September 30, 2021, 3:45pm UTC](https://community.letsencrypt.org/t/issues-with-electron-and-expired-root/160991/6 "2021-09-30T15:45:14Z")

</div>

Aha, foundryvtt! Now this is something I'm excited about getting fixed 😃 You want to pass `--preffered-chain="ISRG Root X1"`, like

```nohighlight
sudo ./certbot certonly --nginx -d foundryvtt.com --dry-run --preferred-chain="ISRG Root X1"

```

That should result in the chain which is _rooted at_ ISRG Root X1, and therefore doesn't include ISRG Root X1 in the `fullchain.pem` itself (chains always stop one cert before the root of trust).

---

_[View the full topic](https://community.letsencrypt.org/t/issues-with-electron-and-expired-root/160991)._
