# Let's Encrypt cert not trusted by Android

**URL:** <https://community.letsencrypt.org/t/lets-encrypt-cert-not-trusted-by-android/58867>\
**Category:** Help\
**Created:** [April 7, 2018, 12:30pm UTC](https://community.letsencrypt.org/t/lets-encrypt-cert-not-trusted-by-android/58867 "2018-04-07T12:30:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Moonlighter](https://avatars.discourse-cdn.com/v4/letter/m/ce7236/32.png) [@Moonlighter](https://community.letsencrypt.org/u/Moonlighter)\
**Post date:** [April 7, 2018, 12:30pm UTC](https://community.letsencrypt.org/t/lets-encrypt-cert-not-trusted-by-android/58867/1 "2018-04-07T12:30:07Z")

</div>

Hello,

So here is my problem, I have a certificate for my site, for the site I use the pem files, however, I have certain software running that requires a .pfx file so i converted the pem files to pfx with open SSL. When I open the site software that uses the .pfx file in a browser (either on Chrome on Android, or in Firefox on my desktop) the cert is trusted, however when I connect with an app to the site, the following information appears in the log:

> java.security.cert.CertPathValidatorException: Trust anchor for certification path not found.

So it seems Android itself does not trust the certificate,

I hope my story is clear and somebody can help me,

Thanks in advance!

Ronald

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [April 7, 2018, 3:55pm UTC](https://community.letsencrypt.org/t/lets-encrypt-cert-not-trusted-by-android/58867/2 "2018-04-07T15:55:33Z")

</div>

Hi @Moonlighter …  
Can you give us your domain name so we can be more efficient in providing help for you?

There is some relevant info on the stack. Please take a look at:

[Trust Anchor not found for Android SSL Connection](https://stackoverflow.com/questions/6825226/trust-anchor-not-found-for-android-ssl-connection#16302527)

Rip

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [April 7, 2018, 4:01pm UTC](https://community.letsencrypt.org/t/lets-encrypt-cert-not-trusted-by-android/58867/3 "2018-04-07T16:01:06Z")

</div>

Hi @Moonlighter,

> [@Moonlighter](#):
>
> I have certain software running that requires a .pfx file so i converted the pem files to pfx with open SSL

How did you convert the certificate to pfx?. You should include the `fullchain.pem` (it includes your cert and the intermediate cert), something like this:

`openssl pkcs12 -export -out certificate.pfx -inkey /etc/letsencrypt/live/yourdomain.tld/privkey.pem -in /etc/letsencrypt/live/yourdomain.tld/fullchain.pem`

Above command will ask for a password.

Hope this helps.

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![Moonlighter](https://avatars.discourse-cdn.com/v4/letter/m/ce7236/32.png) [@Moonlighter](https://community.letsencrypt.org/u/Moonlighter)\
**Post date:** [April 7, 2018, 10:50pm UTC](https://community.letsencrypt.org/t/lets-encrypt-cert-not-trusted-by-android/58867/4 "2018-04-07T22:50:53Z")

</div>

@sahsanu @Rip

Thanks for the replies! You where right sahsanu, I forgot to include the \> fullchain.pem.  
Was automating some things in bash because I’m following a course in programming in R, so I thought I can use this for more, but in my haste forgot the include the \> fullchain.pem

Thanks again, working like a charm right now!

Moonlighter

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 7, 2018, 10:51pm UTC](https://community.letsencrypt.org/t/lets-encrypt-cert-not-trusted-by-android/58867/5 "2018-05-07T22:51:03Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
