I am a Zimbra user and Zimbra refuse to use the new certificates with some messages like :
** Verifying 'cert.pem' against 'privkey.pem'
Certificate 'cert.pem' and private key 'privkey.pem' match.
** Verifying 'cert.pem' against 'fullchain.pem'
ERROR: Unable to validate certificate chain: C = US, O = Internet Security Research Group, CN = ISRG Root X1
error 2 at 2 depth lookup: unable to get issuer certificate
error cert.pem: verification failed
I try the Zimbra validation with chain.pem or fullchain.pem with the same result ...
I test the last recommandation, it is the way I has always installed my certificates, I have more than ten times succeeded, but I can't understand why it does not work now !
I get always that damned messages ** Verifying 'cert.pem' against 'privkey.pem'
Certificate 'cert.pem' and private key 'privkey.pem' match.
** Verifying 'cert.pem' against 'chain.pem'
ERROR: Unable to validate certificate chain: C = US, O = Internet Security Research Group, CN = ISRG Root X1
error 2 at 2 depth lookup: unable to get issuer certificate
error cert.pem: verification failed
The ISRG Root certificate is OK
The ISRG ROOT Certificate is in /etc/ssl/certs :
ISRG_Root_X1.pem -> /usr/share/ca-certificates/mozilla/ISRG_Root_X1.crt
I even have done a "diff" with the ISRG certificate copied from another machine, the two are identical !
Don't understand why the program is "unable to validate".