Lets Encrypt certificate error - 30/09/2021

Boss's iDevices are all not loading an of our Lets Encrypt secured sites, saying they have expired on the 30th of September.

This is the expiration of the DST Root CA X3 that cross signed the Lets Encrypt root CA - ISRG Root x1


The ISRG Root x1 certificate doesn't expire till 2035, and is apparently trusted in iOS 10+ and MacOS 10.12+ but we're still seeing the DST Root CA X3 as the trusted root.


I'm trying to fix it remotely but I can't figure out why its a problem. His macbook, iPad and the big boss's iDevices are also all not working, but all our Windows and Android devices are just fine.


They can't even open the test site - https://valid-isrgrootx1.letsencrypt.org


How do we get these iDevices to work? I feel like we need to somehow push them over to the ISRG root, possibly be deleting the DST root cert but these are BYOD and we have never done any apple device provisioning / MDM so I don't see any way to fix it at all let alone remotely.


I also assume I'm not the only one with this issue but searching for this shows up a lot of info about older devices as its expected to be a problem. an iPhone 12 isn't an old device though so why that's having an issue is confusing - I just need a fix and hopefully others can let me know if their new devices are having issues or not

iPhone 12 Pro Max

Posted on Sep 29, 2021 6:22 PM

Reply

Similar questions

1 reply

Sep 30, 2021 3:43 PM in response to michael_BHC

So my wife's computer is having the same issues. From my search, it looks like the certificate (DST Root CA X3) expired and needs to be updated. Newer devices shouldn't have this problem because they auto-update the certificate, I'm guessing that our devices are not updated and so the certificate is not updated. Interestingly enough this isn't the first time a certificate expired, the last time was May 30th, 2020.


It looks like there are other solutions that are more involved, or maybe those would work on Android/Windows only... Either way updating to the newest OS might be the easiest fix. I'm a little reluctant but the other workaround is changing the Certificate Authority to ISRG Root X1, which is the replacement to DST Root CA X3... and that's about as technical I can get.


I might end up updating but I hope someone tries this out and let us know if it works!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Lets Encrypt certificate error - 30/09/2021

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.