FutureQuest, Inc. FutureQuest, Inc. FutureQuest, Inc.

FutureQuest, Inc.
Go Back   FutureQuest Community > FutureQuest Site Owners (All may read - Only Site Owners May Respond) > Notices & Alerts
User Name
Password  Lost PW

 
Thread Tools Search this Thread Display Modes
Old 09-29-2021, 07:20 PM   Postid: 188539
 Kevin
Systems Administrator
 
Kevin's Avatar
 
Join Date: Aug 2001
Location: Orlando, FL
Posts: 2,986
Problem with Let's Encrypt certificates appearing expired [fixed]

For about 2 hours our Let's Encrypt certificates all appeared to be expired in at least some browsers. We tried with Firefox on Linux, Firefox and Chrome on Windows and both were fine. The trouble was real though. I am guessing that those browsers and possibly others had foreseen this coming and made a special case for it.

The problem was that the certificate used in the chain had expired. The Let's Encrypt people did warn that this was coming here: https://letsencrypt.org/docs/dst-roo...eptember-2021/ I do remember reading that a few months ago and checking and I must have read something backwards because I thought it wasn't going to be an issue for us and then I forgot about it. Luckily it didn't take me long to remember the notice and discover that it really was the problem even if things still worked fine in my browser.

Unfortunately, finding the correct chain file didn't solve the problem. Much of the downtime was due to a problem with our certificate management system. Simply put a chain certificate had never been modified before and the code to do that just didn't work. In the past chain certificates have only ever been replaced by completely new ones leaving the old ones for older certs and the new only applying to new certs. This is why their names tend to end with a number that is incremented.

So, in the end, the tool wouldn't do the job. The data (and other things the tool was supposed to calculate) had to be changed within a MySQL table manually. Anyone who has ever written a MySQL UPDATE query where one of the values is a pasting of a text file will know that the only thing good about that sentence is that it doesn't say binary file.

Our apologies for the outage. Thanks for sending in enough queries quickly enough to make us realize that the problem was real even if we couldn't see it.
__________________
Kevin
Kevin is offline  
Old 10-01-2021, 01:17 PM   Postid: 188544
Mohawk
Site Owner

Forum Notability:
0 pts: Even-handed
[Post Feedback]
 
Join Date: Oct 2013
Posts: 43
Re: Problem with Let's Encrypt certificates appearing expired [fixed]

[Seeing other people in the general thread still having issues...]
Mohawk is offline  
Old 10-01-2021, 01:33 PM   Postid: 188545
Syneryder
Site Owner
 
Syneryder's Avatar

Forum Notability:
283 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Aug 2001
Location: Perth, Australia
Posts: 1,095
Re: Problem with Let's Encrypt certificates appearing expired [fixed]

So, I appear to be one of the people bitten by this as well! I've been using the legacy-tls.futurequest.net for SMTP. This is on a macOS 10.13 machine, and I'm using Postbox 5.0.25. The cert is showing as linking back to DST Root CA X3.

I'm happy to install the new ISRG Root X1 cert manually on this Mac if that will fix things....

EDIT: Turns out I've already got the new ISRG Root X1 cert (expiring 2035) installed after all, but Postbox (based on Thunderbird) needs the certificate added manually. I think I've now fixed it - I downloaded the PEM version of the cert from https://letsencrypt.org/certificates/ and added it in Postbox from Preferences -> Advanced -> Certificates -> View Certificates -> Authorities -> "Import..." and then selecting the PEM file I'd downloaded from Let's Encrypt for ISRG Root X1.

Last edited by Syneryder : 10-01-2021 at 01:49 PM.
Syneryder is offline  


Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:23 AM.


Running on vBulletin®
Copyright © 2000 - 2019, Jelsoft Enterprises Ltd.
Hosted & Administrated by FutureQuest, Inc.
Images & content copyright © 1998-2019 FutureQuest, Inc.
FutureQuest, Inc.