Nginx server sending wrong intermediate chain

  1. I narrow down by debugging top down: what is the single action that I can take to fix the problem? Ans: replace 2 and only 2 files, here on referred to as the elephant
  2. I have been able to clarify every question raised, yet, it was very obvious to me right at the start that there would be no questions or attempts to address this elephant in the room
-----BEGIN CERTIFICATE-----
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
-----END CERTIFICATE-----

That they don't have the same timestamp is unusual as well. Almost as if something later modified fullchain.

Simple, YR cert had openssl verification issues, thus I ran the client again to renew the cert and burnt 6 hours in the process of doing so. My client re-uses existing private keys Live cert does not match with key - #6 by bilogic

you wouldn't need our help.

My problem is already solved, the only reason I'm still replying is in the hope that someone, would address the elephant in the room for everybody's sake.

You're giving it an incorrect certificate chain, perhaps because your DIY client isn't requesting or saving the chain properly; or

Repeat: Fullchain certs are not constructed my client, they are saved as-is directly as received from LE's servers.

From other reports, it sounded like LE is missing some certs in the fullchain

Taken together with the elephant, it is not logical for me to suspect any aspect of the NPM/nginx.