Zimbra renewal - Problems with R3

In my limited understanding, the problem relates to the expiration of the DST Root CA X3. Following the instructions found here, I blacklisted X3 and tried to verify the newly generated certs, but I got the following error:

[zimbra@mail letsencrypt]$ /opt/zimbra/bin/zmcertmgr verifycrt comm privkey.pem cert.pem chain.pem
** Verifying 'cert.pem' against 'privkey.pem'
Certificate 'cert.pem' and private key 'privkey.pem' match.
** Verifying 'cert.pem' against 'chain.pem'
ERROR: Unable to validate certificate chain: cert.pem: C = US, O = Internet Security Research Group, CN = ISRG Root X1
error 2 at 2 depth lookup:unable to get issuer certificate

I also use an old version of Open SSL: OpenSSL 1.0.2l

2 Likes