LetsEncrypt doing something odd?

148 views
Skip to first unread message

Craig Knights

unread,
Sep 29, 2021, 4:19:52 PM9/29/21
to techies-f...@googlegroups.com
So both Chrome and Safari say the cert has expired..  but the expiry is a month away?

NET::ERR_CERT_DATE_INVALID
Subject: kamarweb.mcglashan.school.nz
Issuer: R3
Expires on: 25 Oct 2021
Current date: 30 Sept 2021

anyone?
Craig

Simon Wright

unread,
Sep 29, 2021, 4:24:03 PM9/29/21
to techies-f...@googlegroups.com
Yeah i had the other week.

It's up to date on iis, but on any computer it would have the expired cert.
Can't remember how i resolved it, it was a lot of fumbling. There was an update to the Certify The Web app, so I applied that, re-ran obtaining the cert, checked IIs as using the correct new one, and restarted the server.


Regards,

Simon Wright


--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/CAMueQa2V7b_kDBucQ-dtETOg75jdDUNTQH03tGnGmCuDWf8%2BuQ%40mail.gmail.com.


DISCLAIMER
This e-mail is intended for the addressee only and may contain information which is subject to legal privilege. This e-mail message and accompanying data may contain information that is confidential and subject to privilege. Its contents are not necessarily the official view Otago Boys’ High School or communication of the Otago Boys’ High School. If you are not the intended recipient you must not use, disclose, copy or distribute this e-mail or any information in, or attached to it. If you have received this e-mail in error, please contact the sender immediately or return the original message to Otago Boys’ High School by e-mail, and destroy any copies. Otago Boys’ High School does not accept any liability for changes made to this e-mail or attachments after sending.

David Keenleyside

unread,
Sep 29, 2021, 4:35:30 PM9/29/21
to techies-f...@googlegroups.com
I believe you may be running into the following issue:

More in-depth explanation:

Even more in-depth, with exact certificate that is causing above issue:

image.png
"This is the final date by which everyone must have moved over to using a certificate chain that chains to the ISRG root certificate if you're going to continue to use Let's Encrypt certificates. The old cross-signed X3 and the new cross-signed X3 will have both expired by then and the chain is definitely useless once the root has expired. If you still have legacy client concerns by September 30th, 2021, these clients won't have been updated for over 4.5 years and you will need to convince them to update if they want to continue to be able to access your site/service."

*checks current date* Looks like we have a winner.

Regards,
David.

Craig Knights

unread,
Sep 29, 2021, 4:44:57 PM9/29/21
to techies-f...@googlegroups.com
Yes looks like you are right.

thanks,
Craig

Peter Lambrechtsen

unread,
Sep 29, 2021, 5:18:05 PM9/29/21
to techies-f...@googlegroups.com
I suspect a lot of the internet will have problems with this once the certificate expires in the next few hours.

The main problem is if you don't have the new ISIG X1 loaded into your root chain of trust, and if the intermediate LES R3 isn't loaded either. This should have happened ages ago, but the old certs may not have been removed:


These two files should fix everything loading them into the root CA Certificates. If you have AD it is very straightforward, unmanaged devices, not so much:


Interesting to see how much does stop working or weird "Certificate has expired" warnings come up that folks dutifully ignore.

Happy days.

Peter

Craig Knights

unread,
Sep 29, 2021, 5:55:40 PM9/29/21
to techies-f...@googlegroups.com
Ok. Sorted it. Thanks for the help everyone.

Craig Knights

unread,
Sep 29, 2021, 6:14:38 PM9/29/21
to techies-f...@googlegroups.com
I don't know if anyone else will have this problem...but anyway..

This is on Windows Server.

So in "Manage User Certificates", I removed the expiring tomorrow DST X3 certs, they were in a couple of the folders, only takes 30sec to look in them all.   

I had already run a manual cert renewal in addition to the scheduled one, so I guess that's why the new ones were already there.

That still didn't help, even after clearing the Cache on my test browser and turning off the web services for Kamar

So I nicely shut down the kamar filemaker and rebooted the VM.

Fixed.

thanks all,
Craig

Alistair Baird

unread,
Sep 29, 2021, 6:24:54 PM9/29/21
to techies-f...@googlegroups.com
Thanks Craig, I was heading in that direction. Our Wifi has hung up a lot of windows clients, hopefully this will get us back on track.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.


--
Alistair Baird
IT Manager
St Peters College 
p 06 354 4198
m 021 482 937

Tracy Briscoe

unread,
Sep 29, 2021, 8:21:54 PM9/29/21
to techies-f...@googlegroups.com

This morning we had problems with Macs accessing our websites, but not windows devices.

 

It turned out that even though the webservers had new and old certificates for the R3 Intermediate CA, http.sys (which IIS uses to actually server the web pages) had cached the old certificate and was giving that out to clients as the path to the Root CA.

 

To fix the problem I had to either:

  • Reboot the server
  • Rebind a certificate in IIS

Doing a IIS reset didn’t cause http.sys to refresh it’s cache.

 

It is interesting that the problem only affected Macs. I’m guessing that windows devices had cached the newer R3 intermediate CA certificate, and used that to validate our stpeters.school.nz certificate, whereas the Macs only used what had been provided to it via the webserver.

 

Tracy Briscoe
Senior Network and Systems Engineer

St Peter’s School, Cambridge

Note: This communication may contain privileged and confidential information intended only for the addressee named above. Any views or opinions presented are solely those of the author. If you have received this message in error, we request you delete the message and notify the sender. Please do not distribute, copy or disclose any information. This e-mail has been scanned for viruses but all liability for viruses or similar in any attachment or message is excluded.

St Peter's, Cambridge, New Zealand
Telephone: +64 7 827 9899
Website: www.stpeters.school.nz

Please consider the environment before printing this email

Craig Knights

unread,
Sep 29, 2021, 9:01:10 PM9/29/21
to techies-f...@googlegroups.com
Interesting.  The other one that came up is our onsite accessit library webapp

So I removed the old certs as in my previous email..  but it doesn't use IIS.  It uses Apache Tomcat.


I re-ran the deployment task.  You can't renew the cert, as the certify client says it's not near expiring..

thanks,
Craig



Craig Knights

unread,
Sep 30, 2021, 5:12:59 PM9/30/21
to techies-f...@googlegroups.com
Has anyone got a cheatsheet for the filemaker letsencrypt cert?

Craig Knights

unread,
Sep 30, 2021, 5:23:37 PM9/30/21
to techies-f...@googlegroups.com
nevermind, got it going.  removed the cert from filemaker, then re-ran the powershell script, which died right at the end.. but had already done it's thing..  so reopened the db's and all good.

who ordered the ssl fun for the last day of the term?
cheers,
Craig

Nick Steenson

unread,
Sep 30, 2021, 5:24:06 PM9/30/21
to techies-f...@googlegroups.com
Is that working again now? It stopped working a while back for us and I was told to go without until it's fixed...

Nick



--

Nick Steenson

IT Manager

Mount Aspiring College

T +64 (0) 3 443 0463 (Ext 222)

E stee...@mtaspiring.school.nz
    I...@mtaspiring.school.nz

A 101 Plantation Rd, Wanaka, NZ, 9305
W www.mountaspiringcollege.nz

 

Kevin Campbell

unread,
Sep 30, 2021, 5:47:16 PM9/30/21
to Techies for schools
Just had this hit one of our Fortigates...

Craig Knights

unread,
Sep 30, 2021, 6:24:17 PM9/30/21
to techies-f...@googlegroups.com
the Filemaker-LetsEncrypt-Win-master bluefeathergroup.com one?

i had it there from when i set it up in term1 hols

it worked enough

cheers,
Craig

Peter Lambrechtsen

unread,
Sep 30, 2021, 7:17:45 PM9/30/21
to techies-f...@googlegroups.com
You may need to make sure the new X3 certificate is loaded into your root Certificate Authority chain, and ideally the self signed X1 one too:



With those two certs loaded all weird problems should go away.

Alistair Baird

unread,
Sep 30, 2021, 7:28:36 PM9/30/21
to techies-f...@googlegroups.com
And you may need to reboot the server for good measure. Even though I had all our certs updated and FM web worked, this morning the webserver and Apps aren't working, but the clients are all happy. I'm planning a reboot Monday. Our wifi played up only for Windows clients, all others worked, but worked after a reboot. Shutting down relevant services didn't seem enough.


On Friday, 1 October 2021, Peter Lambrechtsen <pe...@crypt.nz> wrote:
You may need to make sure the new X3 certificate is loaded into your root Certificate Authority chain, and ideally the self signed X1 one too:



With those two certs loaded all weird problems should go away.

On Fri, Oct 1, 2021 at 11:24 AM Craig Knights <craig....@gmail.com> wrote:
the Filemaker-LetsEncrypt-Win-master bluefeathergroup.com one?

i had it there from when i set it up in term1 hols

it worked enough

cheers,
Craig

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.

 

 

DISCLAIMER
This e-mail is intended for the addressee only and may contain information which is subject to legal privilege. This e-mail message and accompanying data may contain information that is confidential and subject to privilege. Its contents are not necessarily the official view Otago Boys’ High School or communication of the Otago Boys’ High School. If you are not the intended recipient you must not use, disclose, copy or distribute this e-mail or any information in, or attached to it. If you have received this e-mail in error, please contact the sender immediately or return the original message to Otago Boys’ High School by e-mail, and destroy any copies. Otago Boys’ High School does not accept any liability for changes made to this e-mail or attachments after sending.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.

Note: This communication may contain privileged and confidential information intended only for the addressee named above. Any views or opinions presented are solely those of the author. If you have received this message in error, we request you delete the message and notify the sender. Please do not distribute, copy or disclose any information. This e-mail has been scanned for viruses but all liability for viruses or similar in any attachment or message is excluded.

St Peter's, Cambridge, New Zealand
Telephone: +64 7 827 9899
Website: www.stpeters.school.nz

Please consider the environment before printing this email

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.


--

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/CACJd5cEstqBceDha9MSFaNeCByV9Kj7stPiFTaytRWD10mCchA%40mail.gmail.com.

Craig Knights

unread,
Sep 30, 2021, 7:32:16 PM9/30/21
to techies-f...@googlegroups.com
Yes Alistair, I had the same this morning after getting the web working yesterday.  I suspect the web to filemaker connection broke during overnight maintenance.  Basically the cert also needed re-imported to Filemaker after yesterday's fixes.

On Fri, Oct 1, 2021 at 12:28 PM Alistair Baird <bai...@stpeterspn.school.nz> wrote:
And you may need to reboot the server for good measure. Even though I had all our certs updated and FM web worked, this morning the webserver and Apps aren't working, but the clients are all happy. I'm planning a reboot Monday. Our wifi played up only for Windows clients, all others worked, but worked after a reboot. Shutting down relevant services didn't seem enough.

On Friday, 1 October 2021, Peter Lambrechtsen <pe...@crypt.nz> wrote:
You may need to make sure the new X3 certificate is loaded into your root Certificate Authority chain, and ideally the self signed X1 one too:



With those two certs loaded all weird problems should go away.

On Fri, Oct 1, 2021 at 11:24 AM Craig Knights <craig....@gmail.com> wrote:
the Filemaker-LetsEncrypt-Win-master bluefeathergroup.com one?

i had it there from when i set it up in term1 hols

it worked enough

cheers,
Craig

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.

 

 

DISCLAIMER
This e-mail is intended for the addressee only and may contain information which is subject to legal privilege. This e-mail message and accompanying data may contain information that is confidential and subject to privilege. Its contents are not necessarily the official view Otago Boys’ High School or communication of the Otago Boys’ High School. If you are not the intended recipient you must not use, disclose, copy or distribute this e-mail or any information in, or attached to it. If you have received this e-mail in error, please contact the sender immediately or return the original message to Otago Boys’ High School by e-mail, and destroy any copies. Otago Boys’ High School does not accept any liability for changes made to this e-mail or attachments after sending.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.

To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.

Note: This communication may contain privileged and confidential information intended only for the addressee named above. Any views or opinions presented are solely those of the author. If you have received this message in error, we request you delete the message and notify the sender. Please do not distribute, copy or disclose any information. This e-mail has been scanned for viruses but all liability for viruses or similar in any attachment or message is excluded.

St Peter's, Cambridge, New Zealand
Telephone: +64 7 827 9899
Website: www.stpeters.school.nz

Please consider the environment before printing this email

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.


--

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.


--
Alistair Baird
IT Manager
St Peters College 
p 06 354 4198
m 021 482 937

--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/CAKQ0vHqAf0UErcX9KTyodyU8Mb%3DXws2pgXDJfXyeFSk5jUSMgQ%40mail.gmail.com.

Tracy Briscoe

unread,
Sep 30, 2021, 8:06:21 PM9/30/21
to techies-f...@googlegroups.com

Yes I had phase two this morning.

 

The Lets Encrypt Root Certificate is in Microsoft’s online CA store, which Windows will automatically download trusted CA certificates from.

The problem was that we follow best practice, and don’t give our servers unlimited Internet access, and hence our servers hadn’t downloaded and trusted ‘ISRG Root X1’ as a Root CA.

When I restarted our reverse proxy server the AD FS proxy wouldn’t come up until I manually added ISRG Root X1 to the trusted CA store.

 

Not the problem I wanted to come into today.

 

Regards,

 

Tracy Briscoe
Senior Network and Systems Engineer

St Peter’s School, Cambridge

 

From: techies-f...@googlegroups.com <techies-f...@googlegroups.com> On Behalf Of Peter Lambrechtsen
Sent: Thursday, 30 September 2021 10:18 am
To: techies-f...@googlegroups.com
Subject: Re: [techies-for-schools] LetsEncrypt doing something odd?

 

I suspect a lot of the internet will have problems with this once the certificate expires in the next few hours.

Jake Wills

unread,
Sep 30, 2021, 9:45:26 PM9/30/21
to Techies for schools
We had the same problem this morning as well... re-import of certificate and restart of FileMaker server fixed it for us.
But looks like Xero may have been caught out with the same thing as well:

Craig Knights

unread,
Sep 30, 2021, 9:49:15 PM9/30/21
to techies-f...@googlegroups.com
ouch, looks like it.  2 million users worldwide.  ouch

Jake Wills

unread,
Sep 30, 2021, 9:51:41 PM9/30/21
to techies-f...@googlegroups.com
Made me feel a lot better about my issues this morning 🤣

You received this message because you are subscribed to a topic in the Google Groups "Techies for schools" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/techies-for-schools/F5Le9nmphFc/unsubscribe.
To unsubscribe from this group and all its topics, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/CAMueQa0cApXWCtEHVmyy1DdGjP959tGNkYuf0ZH0FnrufZ1hcg%40mail.gmail.com.
--
Sent from my phone, so please forgive any typos.

Craig Knights

unread,
Oct 1, 2021, 2:33:20 AM10/1/21
to techies-f...@googlegroups.com

David Keenleyside

unread,
Oct 1, 2021, 6:47:30 AM10/1/21
to techies-f...@googlegroups.com
If you want to follow some of the chaos, plus get a few tips along the way, #letsencrypt is trending well on Twitter:
Various companies caught out are putting up tweets with links to fixes; remember who they are, clearly it doesn't matter how much they are paid, it's a process issue.

A bit of light reading regarding the event, with a few points of interest regarding what is potentially affected which you might not have seen yet; because lockdown.

Note:  I'm subscribed to the letsencrypt mailing list, so this was addressed a fair while ago my end.  However, I highly recommend that if you use something, please make sure you are subscribed to their mailing list in general.  Not only will you avoid issues like today's, but you will also be apprised of security issues and urgent patches.

Regards,
David.

Reply all
Reply to author
Forward
0 new messages