# Still getting "A valid Root CA Certificate could not be located"

**URL:** https://community.letsencrypt.org/t/still-getting-a-valid-root-ca-certificate-could-not-be-located/182295
**Category:** Help
**Created:** [August 4, 2022, 5:37am UTC](https://community.letsencrypt.org/t/still-getting-a-valid-root-ca-certificate-could-not-be-located/182295 "2022-08-04T05:37:23Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![muzicman82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/muzicman82/32/38830_2.png) [@muzicman82](https://community.letsencrypt.org/u/muzicman82)
#### Post date: [August 4, 2022, 5:37am UTC](https://community.letsencrypt.org/t/still-getting-a-valid-root-ca-certificate-could-not-be-located/182295/1 "2022-08-04T05:37:23Z")

</div>

Hello,

I've been making certificates using win-acme. The web server is 4D. Validation is DNS with DreamHost.

Some SSL checkers say the certificate chain is fine and others report that a valid Root CA could not be located. Why? Geocerts is one of them.

Domain is [simon4d.bel.com](http://simon4d.bel.com). Note that this is a different server entirely than [bel.com](http://bel.com), but that hasn't mattered before.

Is it that some validation tools don't trust ISRG Root X1? Can I create certificates which use ISRG Root X2 instead?

I'm creating PEM files with the win-acme tool, and 4D uses the full chain and key files. I am not modifying them.

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [August 4, 2022, 6:01am UTC](https://community.letsencrypt.org/t/still-getting-a-valid-root-ca-certificate-could-not-be-located/182295/2 "2022-08-04T06:01:01Z")

</div>

> [@muzicman82](#):
>
> Can I create certificates which use ISRG Root X2 instead?

That root certificate is more recent and therefore even less well trusted. Besides, it's also cross-signed by ISRG Root X1, so _that_ little fact isn't of that importance.

> [@muzicman82](#):
>
> and 4D uses the full chain

No it doesn't. Your server at `simon4d.bel.com` is only sending the leaf certificate. It might be _configured_ (I dunno) to "see" the full chain, but it isn't using it entirely.

Don't ask me how to change that, as I don't have experience with 4D, win-acme or Windows in general nowadays.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [September 3, 2022, 7:55am UTC](https://community.letsencrypt.org/t/still-getting-a-valid-root-ca-certificate-could-not-be-located/182295/4 "2022-09-03T07:55:17Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
