# SSL Expriry Issue

**URL:** <https://community.letsencrypt.org/t/ssl-expriry-issue/173979>\
**Category:** Help\
**Created:** [March 17, 2022, 7:55am UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979 "2022-03-17T07:55:56Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankur](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@ankur](https://community.letsencrypt.org/u/ankur)\
**Post date:** [March 17, 2022, 7:55am UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/1 "2022-03-17T07:55:56Z")

</div>

We have found that issue in SSL certificate with the proxied domain, universal certificate got renewed yesterday morning, When we are checking open ssl that says it has expired, Can you please check for the issue.

CONNECTED(00000006)  
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3  
verify error:num=10:certificate has expired  
notAfter=Sep 30 14:01:15 2021 GMT  
verify return:0  
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3  
verify error:num=10:certificate has expired  
notAfter=Sep 30 14:01:15 2021 GMT  
verify return:0  
depth=4 O = Digital Signature Trust Co., CN = DST Root CA X3  
verify error:num=10:certificate has expired  
notAfter=Sep 30 14:01:15 2021 GMT  
verify return:0

After disable cloudflare proxied, it started working fine. can you check why it's happen after yesterday certificate renewal.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 17, 2022, 7:58am UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/2 "2022-03-17T07:58:54Z")

</div>

Hello, and welcome.

We need your domain name to check stuff. Also, your OS and openssl versions will be useful.

(I mean, your _client_ OS and OpenSSL versions)

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 17, 2022, 8:00am UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/3 "2022-03-17T08:00:43Z")

</div>

The "DST Root CA X3" certificate has indeed expired. This is intended, it won't be renewed. Please see"

> **[DST Root CA X3 Expiration (September 2021) - Let's Encrypt](https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/)**
>
> Update September 30, 2021 As planned, the DST Root CA X3 cross-sign has expired, and we’re now using our own ISRG Root X1 for trust on almost all devices. For more details about the plan, keep reading! We have also updated our Production Chain...

---

<div class="post-metadata">

**Author:** ![ankur](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@ankur](https://community.letsencrypt.org/u/ankur)\
**Post date:** [March 17, 2022, 8:55am UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/4 "2022-03-17T08:55:08Z")

</div>

clinet os is ubuntu 14.04 and open ssl version OpenSSL 1.0.1f

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 17, 2022, 8:59am UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/5 "2022-03-17T08:59:52Z")

</div>

> [@ankur](#):
>
> ubuntu 14.04

Wtf. That is too old.

Yeah, that error sounds expected.

Check if `ISRG Root X1` is present in your system root store.

---

<div class="post-metadata">

**Author:** ![ankur](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@ankur](https://community.letsencrypt.org/u/ankur)\
**Post date:** [March 17, 2022, 1:04pm UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/6 "2022-03-17T13:04:13Z")

</div>

> [@9peppe](#):
>
> Check if `ISRG Root X1` is present in your system root store

Yes this is avaibale

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 17, 2022, 1:11pm UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/7 "2022-03-17T13:11:49Z")

</div>

Then openssl should not have any issue with that chain. Unless 1.0.1f is one of the old versions that has issues with the "long" chain: [Long (default) and Short (alternate) Certificate Chains Explained](https://community.letsencrypt.org/t/long-default-and-short-alternate-certificate-chains-explained/162526)

Yes, it's this issue (they speak of 1.0.2 but it should be compatible):

> **[Old Let's Encrypt Root Certificate Expiration and OpenSSL 1.0.2 - OpenSSL Blog](https://www.openssl.org/blog/blog/2021/09/13/LetsEncryptRootCertExpire/)**
>
> The currently recommended certificate chain as presented to Let’s Encrypt ACME
> clients when new certificates are issued contains an intermediate …

> In OpenSSL 1.0.x, a quirk in certificate verification means that even clients that trust ISRG Root X1 will fail when presented with the Android-compatible certificate chain we are recommending by default. [#](https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/)

---

<div class="post-metadata">

**Author:** ![Nummer378](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nummer378/32/49862_2.png) [@Nummer378](https://community.letsencrypt.org/u/Nummer378)\
**Post date:** [March 17, 2022, 2:59pm UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/8 "2022-03-17T14:59:12Z")

</div>

> [@ankur](#):
>
> clinet os is ubuntu 14.04 and open ssl version OpenSSL 1.0.1f

Based on best information available to me ([DST Root CA X3 expiry countdown - #24 by xnox](https://community.letsencrypt.org/t/dst-root-ca-x3-expiry-countdown/158964/24)), Ubuntu 14.04 will only validate Let's Encrypts chain if you have access to Ubuntu Extended Security Maintenance (ESM).

I did receive reports multiple months ago that Ubuntu 14.04 without ESM did **not** work. A Ubuntu 16.04 docker container did work (if ca-certificates was fully up to date) even without ESM (which was kinda surprising because xnox stated ESM would be required).

OpenSSL 1.0.1 is in general much more tricky than 1.0.2, because the documented workarounds (remove the old root) are only available on 1.0.2. However Ubuntu does have backported patches to 1.0.1, so Ubuntu is a bit special - with ESM it should work.

If you have access to ESM, ensure that your Ubuntu system is fully updated (especially openssl, libssl and ca-certificates).

Also note that this only matters if your Ubuntu 14.04 system is making outbound TLS client connections to servers using Let's Encrypts long chain. This issue does not matter if you are only hosting a TLS server and clients connecting to you are not using Ubuntu 14.04.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 17, 2022, 7:24pm UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/9 "2022-03-17T19:24:11Z")

</div>

You could try switching to another FREE CA.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 17, 2022, 8:16pm UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/10 "2022-03-17T20:16:30Z")

</div>

Moving to the short chain is a valid solution as well.

But the proper one is upgrading the client.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 16, 2022, 8:16pm UTC](https://community.letsencrypt.org/t/ssl-expriry-issue/173979/11 "2022-04-16T20:16:45Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
