Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: jodywhitesides.com
I ran this command: openssl x509 -text -noout -in cert.pem
It produced this output:Certificate:
Data:
Version: 3 (0x2)
Serial Number:
03:ca:b6:78:1a:b6:9e:4e:35:5b:c0:7f:dd:1c:6d:ad:73:0a
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = Let’s Encrypt, CN = Let’s Encrypt Authority X3
Validity
Not Before: Apr 17 05:14:57 2018 GMT
Not After : Jul 16 05:14:57 2018 GMT
Subject: CN = jodywhitesides.com
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:bd:cb:34:05:da:d0:29:70:b2:e4:32:dc:0f:f6:
d5:5e:49:cb:e4:92:bf:31:e3:f2:3f:69:72:e4:ef:
ef:de:c2:66:c5:f9:7c:39:64:ff:c2:85:37:12:53:
9e:ab:c0:18:ac:47:36:04:f7:1d:a4:ae:90:c7:52:
97:93:53:b0:c0:99:f5:f9:c8:7b:d4:e3:59:fd:ee:
93:5a:56:92:21:62:17:9f:cb:ba:c3:a3:3d:a6:b4:
69:56:13:1b:c0:f6:43:d7:dd:04:89:fa:51:3c:67:
37:49:5f:e0:bc:a4:7b:8f:bb:eb:b4:51:62:b0:c7:
36:ff:28:9e:1c:9d:e1:41:6f:99:4c:41:fc:cf:2f:
b0:85:04:6a:82:c4:39:f8:26:88:5f:fd:e3:b9:21:
0f:76:1c:56:66:89:24:30:ec:a0:3c:b4:64:a4:da:
71:e8:ac:71:7d:f5:d0:99:13:db:2f:ea:ac:3a:cb:
a0:81:a6:ef:a6:d7:0c:d2:11:f5:9c:c4:2f:7c:f2:
a2:0b:82:1f:a6:0b:b0:71:c4:e3:ac:e8:10:e2:b4:
da:2d:ae:17:e2:38:6e:07:62:13:1e:d4:c5:e0:ea:
64:7c:fb:e6:8d:f7:93:3c:52:d4:4f:3c:b3:c5:a9:
f6:44:df:63:4c:7d:cf:57:1b:1b:81:f1:ff:db:28:
f3:3b
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Subject Key Identifier:
83:B0:AD:8F:78:65:C0:28:68:DE:B3:73:31:06:B1:65:C7:97:98:4F
X509v3 Authority Key Identifier:
keyid:A8:4A:6A:63:04:7D:DD:BA:E6:D1:39:B7:A6:45:65:EF:F3:A8:EC:A1
Authority Information Access:
OCSP - URI:http://ocsp.int-x3.letsencrypt.org
CA Issuers - URI:http://cert.int-x3.letsencrypt.org/
X509v3 Subject Alternative Name:
DNS:ftp.jodywhitesides.com, DNS:jodywhitesides.com, DNS:mail.jodywhitesides.com, DNS:www.jodywhitesides.com
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Policy: 1.3.6.1.4.1.44947.1.1.1
CPS: http://cps.letsencrypt.org
User Notice:
Explicit Text: This Certificate may only be relied upon by Relying Parties and only in accordance with the Certificate Policy found at https://letsencrypt.org/repository/
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : DB:74:AF:EE:CB:29:EC:B1:FE:CA:3E:71:6D:2C:E5:B9:
AA:BB:36:F7:84:71:83:C7:5D:9D:4F:37:B6:1F:BF:64
Timestamp : Apr 17 06:14:57.705 2018 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:E3:FF:FB:1D:83:8B:8D:3E:EF:D8:70:
34:83:24:BB:3F:12:C9:6A:53:8C:45:AA:C1:A8:85:7C:
34:76:BA:DC:3E:02:21:00:D6:D9:80:43:C3:80:35:64:
BE:A7:16:52:B8:C3:19:35:12:21:B4:FD:ED:A0:22:B5:
AA:B2:29:DA:2F:40:B7:10
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 29:3C:51:96:54:C8:39:65:BA:AA:50:FC:58:07:D4:B7:
6F:BF:58:7A:29:72:DC:A4:C3:0C:F4:E5:45:47:F4:78
Timestamp : Apr 17 06:14:57.761 2018 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:21:00:91:E6:A2:D2:94:50:65:1D:03:37:56:
75:9D:01:7B:A5:29:73:AD:A0:51:52:06:6E:28:58:CF:
8E:7B:42:91:13:02:20:56:6E:91:71:8A:8D:03:9F:6A:
59:01:F5:AC:D9:98:C7:9B:81:F0:82:24:4A:C9:13:67:
CE:AA:78:00:3D:E5:62
Signature Algorithm: sha256WithRSAEncryption
94:c7:ef:89:45:c8:8c:b9:63:b1:88:14:d0:83:c2:b7:ea:b3:
b4:a0:8c:24:c8:fc:86:74:ce:61:cd:0f:75:3b:49:3b:8c:51:
b2:73:f0:ba:5a:9b:ca:c3:a7:89:a1:46:a0:60:6a:36:9d:6b:
bd:23:28:5a:42:1f:cc:12:b2:ab:37:95:c1:91:81:ba:ea:be:
54:25:6d:62:69:38:44:cf:18:87:b4:8b:6c:b5:3a:c9:a5:eb:
38:74:e2:2a:2c:2b:cf:d0:32:c2:1c:81:ad:22:6a:fc:62:86:
45:95:03:ae:ea:e1:16:df:6e:b0:e7:25:7a:39:58:69:8a:49:
0b:d5:96:49:0f:55:5d:1a:35:73:69:60:b6:ff:da:ff:0e:a6:
6e:f8:09:72:f2:ee:03:59:16:c6:02:af:71:6e:b3:92:70:b0:
a4:9a:20:6b:c9:14:d6:61:17:27:0c:42:1a:4d:05:90:42:b5:
ae:ec:ca:42:fc:50:77:03:73:4d:4d:3c:c9:8f:42:44:e9:48:
ce:23:ae:10:18:c4:c4:98:f1:b3:f8:cd:19:3b:f7:47:25:b9:
15:c6:12:f8:72:ad:04:e4:44:6d:6b:42:33:78:9b:46:f3:4c:
11:98:8d:4e:fc:bb:cf:12:19:ce:3f:67:f8:90:84:3e:42:16:
59:13:ff:d1
My web server is (include version): jodywhitesides.com
The operating system my web server runs on is (include version): Unbuntu 17.10
My hosting provider, if applicable, is:
I can login to a root shell on my machine (yes or no, or I don’t know): yes.
I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no.
I’m running into an issue where I’m attempting to use PHPList for mailing list software. However, PHPList is running into an issue where the TLS certificate from Lets Encrypt is getting rejected due to the following issue:
“io-error: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca”
In getting the information about the Lets Encrypt certs I’ve been issued, I can see that the CA is being set to FALSE. Is there a way to fix this, or to get the CA to be TRUE?
Thank you for any help that can be provided.