PfSense Acme Cert Intermediary chain not accepted with cross signed cert

PfSense Netgate SG-2100 running ...
21.05.1-RELEASE (arm64)
built on Wed Aug 04 09:50:08 EDT 2021

Apache running on RPI 4b but the certificate is offloaded to firewall. When I check the certificate at using godaddy ssl checker or any other checker its says the chain is incomplete (intermediary chain). I have installed the cross linked chain for both certificates in the PfSense Cerftificate manager and using HAProxy to tie to the certificates using the R3.

My hosting provider, if applicable, is: Self hosted at home on RPI4b

Installing certs local with key and point matrix config to the cert.

Hi @spreckoak and welcome to the LE community forum :slight_smile:

I would recheck those steps.
I only see the cert (no chain at all) being served:

echo | openssl s_client -connect | head
depth=0 CN =
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN =
verify error:num=21:unable to verify the first certificate
verify return:1
Certificate chain
 0 s:CN =
   i:C = US, O = Let's Encrypt, CN = R3
Server certificate

