Let's Encrypt DST Root CA X3 has expired
twitter.com
Let's Encrypt DST Root CA X3 has expired
1–10 of 27 posts
Re: Let's Encrypt DST Root CA X3 has expired
#2This is hurting me pretty bad right now, renewing my LE cert is not fixing it via Terraform.
Re: Let's Encrypt DST Root CA X3 has expired
#3This was not a fun morning for me. All of my sites which are running on Debian 9 suddenly weren't able to contact our authentication and other internal systems. I had to disable SSL verification until ops can move them to newer servers.
Re: Let's Encrypt DST Root CA X3 has expired
#4Looking at the number of threads split out from https://community.letsencrypt.org/t/help-thread-for-dst-root...
I think this has been bumpier than they'd hoped.
In particular these two problems don't seem to have been spotted ahead of time:
Android Dns-over-TLS trouble https://community.letsencrypt.org/t/android-devices-with-dot...
Trouble with Electron applications https://community.letsencrypt.org/t/issues-with-electron-and...
Re: Let's Encrypt DST Root CA X3 has expired
#5[deleted]
Re: Let's Encrypt DST Root CA X3 has expired
#6My PoC Xamarin app stopped working today... "The SSL connection could not be established."
Re: Let's Encrypt DST Root CA X3 has expired
#7This was not a fun morning for me. All of my sites which are running on Debian 9 suddenly weren't able to contact our authentication and other internal systems. I had to disable SSL verification until ops can move them to newer servers.
Debian 9 can't be updated to use the new root CA?
Re: Let's Encrypt DST Root CA X3 has expired
#8We got hit with gRPC considering the LE certs as expired: https://github.com/grpc/grpc/issues/27532
Luckily this was quick to fix by just renewing the server cert without the DST root.
Re: Let's Encrypt DST Root CA X3 has expired
#9Twitter is abuzz and not in a good way: https://twitter.com/search?q=letsencrypt&src=typed_query&f=l...
Slack and Shopify seem to be affected.
Re: Let's Encrypt DST Root CA X3 has expired
#10Anybody has an example of website that is running one of the new certificates so we can see if our devices can connect?