<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Expired certificate served (only) to mobile clients!?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I don't understand what is going on:</p>
<p dir="auto">I have haproxy running on my pfsense and connecting to a handful of websites on the backend and I use the pfsense certificate manager to keep my letsencrypt wildcard certificate current.</p>
<p dir="auto">When I access one of my websites from a PC, haproxy serves up a current certificate and the website is shown as secure by my browser.</p>
<p dir="auto">However, when I access any of these websites from my mobile phone, the websites are marked as unsafe because the certificate has expired.</p>
<p dir="auto">So it seems that haproxy does serve up two different certificates (one current, one expired), depending on how the same website is accessed (PC or mobile).</p>
<p dir="auto">I am not sure, but this <em>may</em> have started end of September (when letsencrypt changed their root cerificate). But this may be coincidental and unrelated - no idea.</p>
<p dir="auto">Has anybody had to deal with something like this before or know what is going on?</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/166985/expired-certificate-served-only-to-mobile-clients</link><generator>RSS for Node</generator><lastBuildDate>Fri, 12 Jun 2026 20:59:33 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/166985.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 05 Oct 2021 07:47:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Expired certificate served (only) to mobile clients!? on Tue, 05 Oct 2021 09:28:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>gertjan</bdi></a></p>
<p dir="auto">Thank you, I had seen this thread and followed the OP's advice prior to the expiry of the LE certificate. So I thought I was prepared.</p>
<p dir="auto">But reading again and on, there was a problem reported, not exactly mine but similar enough.</p>
<p dir="auto">(Apparently, my problem was not the certificate itself (as expected by you) but the root or the intermediate certificate (the browser on my phone did not go into those details)).</p>
<p dir="auto">I followed the advice, deleted the CAs and renewed the certificate again. This recreated the CAs and solved my problem.</p>
<p dir="auto">Still strange that I encountered the problems only on my mobile but not on my PC...</p>
]]></description><link>https://forum.netgate.com/post/1004412</link><guid isPermaLink="true">https://forum.netgate.com/post/1004412</guid><dc:creator><![CDATA[sensewolf]]></dc:creator><pubDate>Tue, 05 Oct 2021 09:28:51 GMT</pubDate></item><item><title><![CDATA[Reply to Expired certificate served (only) to mobile clients!? on Tue, 05 Oct 2021 08:15:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/sensewolf">@<bdi>sensewolf</bdi></a> said in <a href="/post/1004397">Expired certificate served (only) to mobile clients!?</a>:</p>
<blockquote>
<p dir="auto">marked as unsafe because the certificate has expired.</p>
</blockquote>
<p dir="auto">The certificate itself, the intermediate or ... the root certificate ?<br />
The last one is already in the "trusted certs list in your phone" and will get updated when you update the phone. Or, if possible, delete it, and get a more recent version.</p>
<p dir="auto">Your using the ACME pfSense package ?<br />
You probably want to look at this thread : <a href="https://forum.netgate.com/category/72/acme">HEADS UP: DST Root CA X3 Expiration (September 2021)</a></p>
]]></description><link>https://forum.netgate.com/post/1004400</link><guid isPermaLink="true">https://forum.netgate.com/post/1004400</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 05 Oct 2021 08:15:40 GMT</pubDate></item></channel></rss>