Clear Cached SSL Certificates

Let's Encrypt DST Root CA X3 and intermediary R3 certificates have expired a couple days ago. I have a Plex server that uses a certificate from Let's Encrypt but it is signed by ISRG instead of DST. When I visit the site with an iOS or tvOS device I get a certificate error. Using the TLS Inspector app on my iPhone I am able to see that my Plex certificate is valid but the R3 and DST CA is expired causing it to fail. If I visit the site on a iOS device that never visited it before it works and I can see the certificate is valid. If I factory reset a device that isn't working then, after reinstalling, it works. This all points me to my device is caching the old intermediary and root certificate and refusing to update.


My question is how do I clear cached certificates on an AppleTV or iPhone? So far I have tried clearing Safari's cache, resetting the network settings, removing and reinstalling the app, and restarting the device and none of these have worked. This is different than if I manually trusted a certificate or have a certificate installed via a profile.


More info on the expired certificates can be found here:

https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/


Safari shows this when I view the certificate:


More Details shows this:



As you can see the Plex certificate is valid but it shows it as expired. I used TLS Inspector to see the certificate chain and it shows this:


If I visit the same site on a non Apple device it shows the correct certificate chain:



[Image Edited by Moderator to Remove Personal Information]


Posted on Oct 3, 2021 7:16 PM

Reply

Similar questions

1 reply

Nov 16, 2021 12:59 AM in response to choeschen

This is very annoying. Lost about one whole week digging through the internet. Visiting the same site on a Mac with Firefox works fine -> FF has it‘s own certificates management.


I think the problem lays in the shared Trust Store. There you can still find the expired certificate. And if a device used this once for a site, it tries to use it again.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Clear Cached SSL Certificates

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.