Resolving issue with LetsEncrypt root certificate

  Print

Temporary solution for resolving issue with LetsEncrypt root certificate


This guide should only be followed if you have a LetsEncrypt SSL certificate and started having connection issues after 30/09/2021.

On September 30 2021, Let's Encrypt updated their ROOT certificate. This has caused various issues with connectivity for email clients and web traffic, often with a message about an 'expired certificate'. As per their press release (below), the old root certificate 'ISRG Root X1' expired on 30/09/2021 and was updated from their side.
https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/

However, any LetsEncrypt SSL Certificates that are currently in use will still show the old, now-invalid certificate in their CA Bundle. To get emails and web traffic working as normal again, the most straightforward solution is to uninstall and reinstall your current certificate, but download the new CA Bundle.



Step 1 - Log into cPanel and click on SSL/TLS.

0b4cf1e4af92dbf2c15b56a7d43ade2b1ac332f49e0cb3d37f5e03eca0f86749054a1683c4f3e5d9?t=ac89127b6d1ad8aca25296e3d6698b8b


Step 2 - Select Manage SSL Sites.
043a6167930e025cfcfc5b31381ea846ae2243522cba5093e08c2be20c63946d2b2460194080019b?t=1750f063e1eec4d0a5aeafb37e57855c


Step 3 - Under 'Manage Installed SSL Websites', select Uninstall.

d0acf72c1127ec6e63a3a780ce1a1b107460cfede501e977b43d81c38b76b49e09c86e913270ff45?t=36740c06189b1e0aebf86576a9882b9b


Step 4 - Select Proceed.
f5b3256dde9865246b0354fce4062e0b8c8aece6c9750c513adddc1e66d5a48f903f07926d04678b?t=a3b4fdc9711c22c0388e30bd62c6df40


Step 5 - Further down the page under 'Install an SSL Website', Select the domain corresponding to the SSL Certificate you just uninstalled.

cb579bc97af57f5a56b2093d2d755ec62751b787ef36cfd4f2ed099551f7ac3bdb834438464d42c3?t=785012859515db2aba76284adad90614


Step 6 - Select Autofill by domain.

3f63c1b20469b58c4ece00a7c38c7b216b3ebb9b5f6935a5bcd6089c6e3aab1c883c0191f1fe9087?t=1f48670270a1f1ae15931689f930bf8d


Step 7 - Remove the contents of the Certificate Authority Bundle box as below. Leave the other boxes as they are.

54f38fc763a94a864f115dc0b94a80dc850cda7baa4af2c3ff30de7ec2ed23279d3d04530793b270?t=57e78087c64b3ae67bd25571a3727485

Step 7 - Select Install.

759ef80ed2a2db7fd159b5059107b801bff68f933d7c34cf263cd4b5f364ca6b36b76954be66dee0?t=367c38f7983fc30365596c60b183bd41

This will reinstall the same certificate, but force a re-download of the CA Bundle containing the updated LetsEncrypt ROOT Certificate.

After this has been done, allow a few minutes and restart your email clients, then try to connect again. This should resolve the issue, and we will post more details to our status page as they become available.


Thank you for your feedback on this article.

Related Articles

© Crucial