# Problem connecting to server

**URL:** https://community.letsencrypt.org/t/problem-connecting-to-server/217537
**Category:** Help
**Created:** [May 1, 2024, 2:53pm UTC](https://community.letsencrypt.org/t/problem-connecting-to-server/217537 "2024-05-01T14:53:56Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![mike\_e](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@mike\_e](https://community.letsencrypt.org/u/mike_e)
#### Post date: [May 1, 2024, 2:53pm UTC](https://community.letsencrypt.org/t/problem-connecting-to-server/217537/1 "2024-05-01T14:53:56Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [fensoft.co.uk](http://fensoft.co.uk)

I ran this command: curl -v [https://acme-staging-v02.api.letsencrypt.org/directory](https://acme-staging-v02.api.letsencrypt.org/directory)  
(The curl version is 8.4.0)

It produced this output:

- Trying 172.65.46.172:443...
- Connected to [acme-staging-v02.api.letsencrypt.org](http://acme-staging-v02.api.letsencrypt.org) (172.65.46.172) port 443
- ALPN: curl offers http/1.1
- Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH
- TLSv1.2 (OUT), TLS handshake, Client hello (1):
- CAfile: none
- CApath: /etc/ssl/certs
- TLSv1.2 (IN), TLS handshake, Server hello (2):
- TLSv1.2 (IN), TLS handshake, Certificate (11):
- TLSv1.2 (OUT), TLS alert, unknown CA (560):
- SSL certificate problem: unable to get local issuer certificate
- Closing connection
- TLSv1.2 (OUT), TLS handshake, Client hello (1):
- TLSv1.2 (IN), TLS handshake, Server finished (14):
- TLSv1.2 (OUT), TLS alert, unexpected\_message (522):
- TLSv1.2 (OUT), TLS alert, close notify (256):  
curl: (60) SSL certificate problem: unable to get local issuer certificate  
More details here: [curl - SSL CA Certificates](https://curl.se/docs/sslcerts.html)

My web server is (include version): apache 2.4.20

The operating system my web server runs on is (include version): Slackware Linux 14.2

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

---

<div class="post-metadata">

### Author: ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)
#### Post date: [May 1, 2024, 3:06pm UTC](https://community.letsencrypt.org/t/problem-connecting-to-server/217537/2 "2024-05-01T15:06:36Z")

</div>

It looks like your system trust store doesn't include ISRG Root X1, the root that all of Let's Encrypt's certificates (including those we issue to ourselves for our own API servers) chain up to.

Slackware 14.2 is from 2016, and ships with both a very old certificate trust store, _and_ an old and unsafe version of openssl. I would advise updating to Slackware 15.0. If you can't do that, it [should be safe](https://www.linuxquestions.org/questions/slackware-14/can-i-update-ca-certificates-on-14-2-a-4175645115/) to install the `-current` version of the ca-certificates package.

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [May 1, 2024, 3:08pm UTC](https://community.letsencrypt.org/t/problem-connecting-to-server/217537/3 "2024-05-01T15:08:34Z")

</div>

_Or_ some kind of untrusted MachineInTheMiddle is trying to hijack the connection, e.g. anti-virus on the device itself or a firewall doing deep packet inspection on HTTPS somewhere on the premises, ISP or on a government level.

Knowing which certificate is unrecognised by cURL would help to distinguish what's what.

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [May 1, 2024, 3:09pm UTC](https://community.letsencrypt.org/t/problem-connecting-to-server/217537/4 "2024-05-01T15:09:34Z")

</div>

What shows?:  
`openssl s_client -connect acme-staging-v02.api.letsencrypt.org:443 | head -n 20`

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [May 31, 2024, 3:10pm UTC](https://community.letsencrypt.org/t/problem-connecting-to-server/217537/5 "2024-05-31T15:10:33Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
