Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Certificate Updated CA - R11 still pointing to ISRG Root X1

    Scheduled Pinned Locked Moved ACME
    2 Posts 1 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jrey
      last edited by

      My Let's Encrypt certificate renewed again last night on time and as expected. This has been working well. And the certificate works in all areas I use it in.

      Screen Shot 2024-08-16 at 9.25.29 AM.png

      The Certificate Authority (chain) however doesn't seem correct as the R11 still chains up to ISRG Root X1 which is set to expire in Sept

      Screen Shot 2024-08-16 at 9.26.58 AM.png

      I confirmed the "1" certificate count shown on the ISRG Root X1 by looking first in the config.xml and checking the R11 caref attribute does in fact point to the refid of the X1 certificate.
      Second check was then looking at the chain in a browser the is using the certificate
      Screen Shot 2024-08-16 at 9.36.37 AM.png

      Have I missed something? the renewal process has been working fine for several cycles (months, even on prior versions). Currently on 24.03 and acme is at 0.8_1

      Thanks

      J 1 Reply Last reply Reply Quote 0
      • J
        jrey @jrey
        last edited by

        Resolved

        Found some documentation on Let's Encrypt (I really though the CA change would be handled automatically, apparently not)

        What I did was grab the pem they have listed, create a new CA with the same name, paste the pem and save the new CA

        The chain "Certificates" immediately changed to the new CA removing the count of 1 from the Sept 2024 soon to expire CA and assigning it to the new one (likely would have been fine to just replace the cert pem data in the original and update it.)

        Screen Shot 2024-08-16 at 10.49.12 AM.png

        1 Reply Last reply Reply Quote 5
        • J jrey referenced this topic on
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.