• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

ISRG Root X1 not updated to self-signed version

ACME
4
6
637
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    AMG A35
    last edited by Jun 9, 2024, 12:40 PM

    I run Plus 24.03-RELEASE, with all current patches along with acme 0.8_1. I use acme to source Let’s Encrypt certificates for several domains with Cloudflare DNS.

    After the Let’s Encrypt “Chains of Trust” changes from 6 June 2024 I have renewed all my certificates which now have intermediate CAs of ISRG R10 or Rll, I have deleted the old R3 CA.

    Certificate manager is still showing ISRG Root X1 valid from 20 Jan 2021 to 30 Sept 2024 i.e. the cross-signed version, not the self-signed version valid from 4 June 2015 to 4 June 2030.

    I have tried adding a new domain via acme but that has used the existing ISRG Root X1.

    Will acme automatically update ISRG Root X1 before 30 Sept 2024 or do I need to act?

    If action is required, can I simply paste the self-signed pem contents into the existing CA entry for ISRG Root X1?

    login-to-view

    1 Reply Last reply Reply Quote 3
    • P
      PatRyan
      last edited by Sep 14, 2024, 6:25 AM

      Did you ever figure this out? I have the same question and September 30 is getting closer every day.

      A 1 Reply Last reply Sep 14, 2024, 8:42 AM Reply Quote 0
      • A
        AMG A35 @PatRyan
        last edited by Sep 14, 2024, 8:42 AM

        @PatRyan I pasted the self-signed pem contents into the existing CA entry for ISRG Root X1 and all has been fine.

        A 1 Reply Last reply Sep 16, 2024, 4:42 AM Reply Quote 0
        • D
          Dredex
          last edited by Sep 14, 2024, 12:06 PM

          I personally deleted the existing CA entry for ISRG Root X1, all seems to be working fine and certs are renewing.

          1 Reply Last reply Reply Quote 0
          • A
            accidentallyadmin @AMG A35
            last edited by Sep 16, 2024, 4:42 AM

            @AMG-A35 Could you please explain where to get this self-signed pem contents and where to put them into?

            A 1 Reply Last reply Sep 16, 2024, 9:27 AM Reply Quote 0
            • A
              AMG A35 @accidentallyadmin
              last edited by Sep 16, 2024, 9:27 AM

              @accidentallyadmin Looking at posts here and Reddit looks like simply deleting ISRG Root X1 and the renewing certificates works fine.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.