Letsencrypt certificate chain in AWS API Gateway custom domain trust store

My domain is:letsencrypt-mtlsclient1.abhidhya.com

I ran this command: Trying to use this certificate for mTLS set up in API Gateway, but I'm getting warning saying there are 2 invalid certificate in your trust store bundle. Not sure if there is an issue with the chain as I think ISRG Root X is issued by DST Root CA X3, but that certificate seems to have expired.

What would be correct chain for Letsencrypt certificates issued by R3.

Which ACME client did you use?
Which cert files did you use?


Used certbot. I tried both chain and full chain.

