# OpenSSL/Browser still showing 'Certificate Exipred' after renwal by certbot

**URL:** <https://community.letsencrypt.org/t/openssl-browser-still-showing-certificate-exipred-after-renwal-by-certbot/192410>\
**Category:** Help\
**Created:** [February 7, 2023, 12:47pm UTC](https://community.letsencrypt.org/t/openssl-browser-still-showing-certificate-exipred-after-renwal-by-certbot/192410 "2023-02-07T12:47:14Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 7, 2023, 6:25pm UTC](https://community.letsencrypt.org/t/openssl-browser-still-showing-certificate-exipred-after-renwal-by-certbot/192410/6 "2023-02-07T18:25:23Z")

</div>

> [@Georglange](#):
>
> Again, thank you! This problem does not longer exist and this thread can be marked as solved (if there is here such a thing).

You can mark any of the posts as the Solution from the bottom menu in each post

> [@Georglange](#):
>
> The only thing i am still a bit worried about is: why did openssl come back with an expired-error when elsewhere everything had already been fine?

What openssl version is it? It might just be an old one that reports it that way. Although, I checked with openssl 3.0.2 and a 1.0.2k and neither reports like that.

Was that the entire openssl output related to the cert and chain? (don't need to see the actual cert) Because usually each step of the chain is shown and that DST cert in the chain is not usually depth 1.

It might be related to how your openssl is handling the extra leaf cert which you should remove

Note there is an expired cert in the chain (DST Root CA X3) which is for compatibility for older Android devices. It is included in the default chain from Let's Encrypt. In fact, this website even uses that default chain. It's possible this could cause problems with certain clients and you could consider the "short chain" instead.

Certbot can return the short chain with the `--preferred-chain "ISRG Root X1"` option.

More info on these chains is here:

> [@Long (default) and Short (alternate) Certificate Chains Explained](https://community.letsencrypt.org/t/long-default-and-short-alternate-certificate-chains-explained/162526):
>
> I…

---

_[View the full topic](https://community.letsencrypt.org/t/openssl-browser-still-showing-certificate-exipred-after-renwal-by-certbot/192410)._
