# SSL Certificate error iis

**URL:** <https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506>\
**Category:** Help\
**Created:** [December 2, 2017, 11:44am UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506 "2017-12-02T11:44:59Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![allam](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@allam](https://community.letsencrypt.org/u/allam)\
**Post date:** [December 2, 2017, 11:44am UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/1 "2017-12-02T11:44:59Z")

</div>

Hi

After configuring my server to use Let’s Encrypt certificate. It working perfectly fine on Google Chrome desktop browser.

But on android google chrome I have getting error.

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/8/5/85e6cbccba508c3877be2926b97f9fc2a34b8d2d.png)  
the server us iis

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [December 2, 2017, 1:29pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/2 "2017-12-02T13:29:08Z")

</div>

You’re using, sort of, the “wrong” intermediate certificate:

```
Certificate chain
 0 s:/CN=ebank.reb.sy
   i:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
 1 s:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
   i:/C=US/O=Internet Security Research Group/CN=ISRG Root X1

```

While the `ISRG Root X1` is indeed the root certificate of Let’s Encrypt itself, it’s currently not present in _all_ root certificate stores. Some, like Mozilla (and apparently Chrome too), do have it included (only recently), but others like Android or Internet Explorer don’t.

Therefore, Let’s Encrypt has _cross-signed_ their intermediate certificates with the `DST Root CA X3` (IdenTrust) certificate. That root certificate is present in mostly all root certificate stores.

You can read more about the cross-signing here: [https://letsencrypt.org/certificates/](https://letsencrypt.org/certificates/)

To mitigate your current problem, you’ll need to send the following intermediate (see site above): “Let’s Encrypt Authority X3 (IdenTrust cross-signed)”.

How to do that on IIS? That, I don’t know…

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [December 2, 2017, 10:14pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/3 "2017-12-02T22:14:58Z")

</div>

Follow the instructions in step 1 of this guide to access the certificate manager for the system user:

[https://support.microsoft.com/en-us/help/954755/how-to-configure-intermediate-certificates-on-a-computer-that-is-runni](https://support.microsoft.com/en-us/help/954755/how-to-configure-intermediate-certificates-on-a-computer-that-is-runni)

Before completing step 2, look in _Intermediate Certificate Authorities_ for any entries starting with _Let’s Encrypt Authority_ and delete them.

Then follow the instructions in step 2 to import the correct intermediate, which you can [download here](https://letsencrypt.org/certs/lets-encrypt-x3-cross-signed.pem). (Change the file extension to `.cer` or choose `All Files (*.*)` to use the PEM file with the certificate manager.)

---

<div class="post-metadata">

**Author:** ![allam](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@allam](https://community.letsencrypt.org/u/allam)\
**Post date:** [December 3, 2017, 1:21pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/4 "2017-12-03T13:21:04Z")

</div>

same result, but if the let 's encrypt certificate install on Linux it  
works fine on the Android browser, in addition, two firefoxes on Android  
work fine with Apache and IIS.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [December 3, 2017, 2:06pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/5 "2017-12-03T14:06:14Z")

</div>

> [@allam](#):
>
> same result

You're still sending the ISRG Root signed intermediate.

---

<div class="post-metadata">

**Author:** ![allam](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@allam](https://community.letsencrypt.org/u/allam)\
**Post date:** [December 3, 2017, 6:13pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/6 "2017-12-03T18:13:59Z")

</div>

I do all the steps before please can you provide me full details to solve  
this issue.

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [December 3, 2017, 6:42pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/7 "2017-12-03T18:42:41Z")

</div>

You were very careful to follow the specific instructions to get to the certificate manager for the _system user_, correct? (If you just shortcut into the Certificate Manager in the Start Menu you will not affect the right certificate store.)

What program or website did you use to obtain your certificate?

Did you allow that program to install the certificate for you automatically or did you install it manually?

If you installed it manually, what steps did you take to install it into IIS? Do you remember the name of the file(s) you imported or still have a copy of them?

---

<div class="post-metadata">

**Author:** ![allam](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@allam](https://community.letsencrypt.org/u/allam)\
**Post date:** [December 3, 2017, 7:11pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/8 "2017-12-03T19:11:04Z")

</div>

I generate a certificate and import it to personal by use MMC o windows  
then I select the certificate under IIS web server to assign to our  
website.

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [December 4, 2017, 4:53am UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/9 "2017-12-04T04:53:40Z")

</div>

have a look at this article

[https://www.linkedin.com/pulse/lets-encrypt-part-1-issuing-installing-certificates-andrei-hawke/](https://www.linkedin.com/pulse/lets-encrypt-part-1-issuing-installing-certificates-andrei-hawke/)

looks like you got things sorted.

---

<div class="post-metadata">

**Author:** ![gotham](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/gotham/32/16320_2.png) [@gotham](https://community.letsencrypt.org/u/gotham)\
**Post date:** [December 4, 2017, 7:46am UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/10 "2017-12-04T07:46:10Z")

</div>

@allam  
Are you using any windows client for generating certificates ?

---

<div class="post-metadata">

**Author:** ![allam](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@allam](https://community.letsencrypt.org/u/allam)\
**Post date:** [December 4, 2017, 5:30pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/11 "2017-12-04T17:30:45Z")

</div>

yes we use [https://zerossl.com/](https://zerossl.com/)

---

<div class="post-metadata">

**Author:** ![rise](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rise](https://community.letsencrypt.org/u/rise)\
**Post date:** [December 4, 2017, 9:17pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/12 "2017-12-04T21:17:13Z")

</div>

hello I am very new here- and also new to SSL problems ! I am working on a wordpress site and was blocked out from my site due to the same errormessage as here - and found I need a ssl certificate

- I am on a danish group who refered me to this group.  
Can anyone help and totally newbie who needs a SSLcentification ?  
I have no idea of what to do and how - when it comes to this and would apprecaite some help  
Thanx in advance 😉  
Rise

---

<div class="post-metadata">

**Author:** ![gotham](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/gotham/32/16320_2.png) [@gotham](https://community.letsencrypt.org/u/gotham)\
**Post date:** [December 5, 2017, 2:19pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/13 "2017-12-05T14:19:07Z")

</div>

@rise  
please do not hijack this thread. please try opening another thread

---

<div class="post-metadata">

**Author:** ![gotham](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/gotham/32/16320_2.png) [@gotham](https://community.letsencrypt.org/u/gotham)\
**Post date:** [December 5, 2017, 2:21pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/14 "2017-12-05T14:21:03Z")

</div>

@allam  
for windows 2012 r2 i am using letsencrypt-win-simple . try using it

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [December 5, 2017, 11:08pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/15 "2017-12-05T23:08:08Z")

</div>

You used the LE32.exe or LE64.exe downloads and not their online wizard?

Did you pass the `--export-pfx` option to it in order to generate a PFX file for IIS or did you import some other file it generated?

---

<div class="post-metadata">

**Author:** ![allam](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@allam](https://community.letsencrypt.org/u/allam)\
**Post date:** [December 6, 2017, 8:02am UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/16 "2017-12-06T08:02:34Z")

</div>

I didn’t use the LE32.exe or LE64.exe downloads I enable check export pfx

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [December 6, 2017, 5:33pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/17 "2017-12-06T17:33:05Z")

</div>

Thanks, it was important to confirm you were following a procedure that would import the right intermediate.

I guess this is a similar issue to one previously where even following Microsoft’s procedure was not good enough.

Try [following the instructions in this thread](https://community.letsencrypt.org/t/iis-8-5-building-incorrect-chain-with-lets-encrypt-authority-x3/13320/84?u=patches) except you need to delete the Let’s Encrypt Authority X3 instead of the old X1 intermediate described there. Go ahead and import the correct X3 intermediate you downloaded earlier as it suggests as well.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [January 5, 2018, 5:33pm UTC](https://community.letsencrypt.org/t/ssl-certificate-error-iis/47506/18 "2018-01-05T17:33:19Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
