<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>www.ritlabs.com [Topic: Getting 'certificate expired' message when the certificate is NOT expired.]</title>
		<link>http://www.ritlabs.com</link>
		<description>New posts in Getting 'certificate expired' message when the certificate is NOT expired. of  forum at www.ritlabs.com [www.ritlabs.com]</description>
		<language>en</language>
		<docs>http://backend.userland.com/rss2</docs>
		<lastBuildDateTag>Thu, 28 Apr 2022 01:53:34 +0300</lastBuildDateTag>		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message53267/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_9ApBjXIf" href="/en/forums/" bx-tooltip-user-id="45726">pierrevg</a> wrote:<br /><noindex><a href="https://www.ritlabs.com/en/news/7666/" target="_blank" rel="nofollow">https://www.ritlabs.com/en/news/7666/</a></noindex> &nbsp; &nbsp; -&gt; 404 <img src="http://www.ritlabs.com/bitrix/images/main/smiles/5/icon_sad.gif" border="0" data-code=":(" data-definition="SD" alt=":(" style="width:16px;height:16px;" title="" class="bx-smile" /><br /><br />=============<br /><br />This was an old problem and the file was probably removed because it was no longer relevant. btw, the issue discussed here was also discussed in another topic: <noindex><a href="https://www.ritlabs.com/en/forums/forum4/topic15458/" target="_blank" rel="nofollow">https://www.ritlabs.com/en/forums/forum4/topic15458/</a></noindex><br /><br />Are you having this same problem and if so, have you tried the suggestions offered here? If you have, which version of The Bat do you have? <br />
			<i>28 April 2022 01:53:34, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message53267/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message53267/</guid>
			<pubDate>Thu, 28 Apr 2022 01:53:34 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message53259/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Hi,<br /><noindex><a href="https://www.ritlabs.com/en/news/7666/" target="_blank" rel="nofollow">https://www.ritlabs.com/en/news/7666/</a></noindex> &nbsp; &nbsp;-&gt; 404 <img src="http://www.ritlabs.com/bitrix/images/main/smiles/5/icon_sad.gif" border="0" data-code=":(" data-definition="SD" alt=":(" style="width:16px;height:16px;" title="" class="bx-smile" /><br /><br />Thanks <br />
			<i>27 April 2022 14:41:46, <a href="http://www.ritlabs.com/en/forums/">pierrevg</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message53259/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message53259/</guid>
			<pubDate>Wed, 27 Apr 2022 14:41:46 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52362/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_04QqVUNR" href="/en/forums/" bx-tooltip-user-id="311">Daniel van Rooijen</a> wrote:<br /> &nbsp;Everyone: Please see the official notification by Ritlabs, which offers yet another good solution: <br /><br /> <noindex><a href="https://www.ritlabs.com/en/news/7666/" target="_blank" rel="nofollow">https://www.ritlabs.com/en/news/7666/</a></noindex> &nbsp;<br />=============<br />I can confirm that the official solution by replacing the .ABD file works as well <img src="http://www.ritlabs.com/bitrix/images/main/smiles/5/icon_smile.gif" border="0" data-code=":)" data-definition="SD" alt=":)" style="width:16px;height:16px;" title="" class="bx-smile" /><br /><br />The .ABD file is actually the whole Trusted Root CA address book entry. The devs added the ISRG Root X1 &quot;contact&quot; (as I described in post #16), and updated the DST Root CA X3 contact by importing the same new certificate (as I described in post #6) and deleting the old certificate.<br /><br />I seem to have accumulated many more entries in Trusted Root CA than there are in the provided version, so I&#39;ll stick with my old manually updated one just in case. <br />
			<i>02 October 2021 10:15:47, <a href="http://www.ritlabs.com/en/forums/">Miloš Radovanović</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52362/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52362/</guid>
			<pubDate>Sat, 02 Oct 2021 10:15:47 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52361/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<B><span class="bx-font" style="color:#EE1D24">Everyone: Please see the official notification by Ritlabs, which offers yet another good solution:</span><br /><br /><noindex><a href="https://www.ritlabs.com/en/news/7666/" target="_blank" rel="nofollow">https://www.ritlabs.com/en/news/7666/</a></noindex></B> <br />
			<i>01 October 2021 20:33:36, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52361/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52361/</guid>
			<pubDate>Fri, 01 Oct 2021 20:33:36 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52360/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_wOu6gEFM" href="/en/forums/" bx-tooltip-user-id="128936">Beatrice Boucher</a> wrote:<br />I just would think that receiving an updated-file (with correct dates) would just be the best service.<br />=============<br /><br />Well, I doubt if Ritlabs would re-release older versions with the new certificate. Instead, I'd expect that the new certificate will be included in the next version, but that would force you to upgrade to that latest version.<br /><br /><br />====quote====<br />I would also like to know more on the consequences of using Windows certificate and getting MS CryptoAPI &nbsp;(option2).<br />=============<br /><br />Theoratically, using The Bat's private certificate store is more secure. The one built into Windows, that is used by most applications, is an interesting target for skilled hackers, and several exploits have been found in the past. Those do not affect The Bat because it has its own encryption/decryption/verification routines and its own store of certificates. Still, if you're not guarding national secrets, I wouldn't worry about it. <br />
			<i>01 October 2021 19:32:42, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52360/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52360/</guid>
			<pubDate>Fri, 01 Oct 2021 19:32:42 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52356/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_gNKF6VR9" href="/en/forums/" bx-tooltip-user-id="128897">Miloš Radovanović</a> wrote:<br />[..] here are the steps for the "cleaner" solution for option1:<br />=============<br /><br />Many thanks for this fool-proof solution! <br />
			<i>01 October 2021 18:34:57, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52356/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52356/</guid>
			<pubDate>Fri, 01 Oct 2021 18:34:57 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52354/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_cbg8W2mY" href="/en/forums/" bx-tooltip-user-id="128936">Beatrice Boucher</a> wrote:<br />Hi, I have exactly the same problems. I am using the BAT version 9.3.4. (64 bits). <br /><br />I do not want to get into technical-stuff (no my hobby), though I understand from my login-logs that the BAT certificate expired yesterday. as you can see hereunder. <br /><br />&gt;1-10-2021, 12:31:45: SEND &nbsp;- Basis: &quot;Digital Signature Trust Co.&quot;, &quot;DST Root CA X3&quot; &nbsp; &nbsp; Geldig van 30-9-2000 21:12:1 &nbsp;9 &nbsp; &nbsp;tot 30-9-2021 &nbsp;14:01:15. Dit S/MIME certificaat is verlopen! <br />!1-10-2021, 12:31:45: SEND &nbsp;- TLS handdruk mislukt. Ongeldig servercertificaat (Dit S/MIME certificaat is verlopen).<br /><br />I just would think that receiving an updated-file (with correct dates) would just be the best service.<br /><br /><br />I would also like to know more on the consequences of using Windows certificate and getting MS CryptoAPI &nbsp;(option2).<br /><br /><br />Thanks.<br />=============<br />I can&#39;t help with the question on option2, but here are the steps for the &quot;cleaner&quot; solution for option1:<br /><br />a) Download <noindex><a href="https://letsencrypt.org/certs/isrgrootx1.der" target="_blank" rel="nofollow">https://letsencrypt.org/certs/isrgrootx1.der</a></noindex><br />b) In The Bat!, make sure that Internal Implementation is selected in Options -&gt; S-MIME and TLS...<br />c) Tools -&gt; Address Book<br />d) If Trusted Root CA is not visible in the Address Book, select View -&gt; Certificate Address Books<br />e) Select Trusted Root CA, click Create New Contact<br />f) Tab General: enter &quot;ISRG Root X1&quot; in field First name, select &quot;User-defined&quot; in field Display name<br />g) Tab Business: enter &quot;Internet Security Research Group&quot; in field Company Name<br />h) Tab Certificates: Import... and select the downloaded file <br />
			<i>01 October 2021 16:34:16, <a href="http://www.ritlabs.com/en/forums/">Miloš Radovanović</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52354/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52354/</guid>
			<pubDate>Fri, 01 Oct 2021 16:34:16 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52350/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Hi, I have exactly the same problems. I am using the BAT version 9.3.4. (64 bits). <br /><br />I do not want to get into technical-stuff (no my hobby), though I understand from my login-logs that the BAT certificate expired yesterday. as you can see hereunder. <br /><br />&gt;1-10-2021, 12:31:45: SEND &nbsp;- Basis: &quot;Digital Signature Trust Co.&quot;, &quot;DST Root CA X3&quot;<span class="bx-font" style="color:#ff0000"> </span><span class="bx-font" style="color:#ff0000"><span class="bx-font" style="color:#ff0000">Geldig van 30-9-2000 21:12:1</span><span class="bx-font" style="color:#ff0000">9</span> </span><span class="bx-font" style="color:#ff0000">tot 30-9-2021</span> 14:01:15. Dit S/MIME certificaat is verlopen! <br />!1-10-2021, 12:31:45: SEND &nbsp;- TLS handdruk mislukt. Ongeldig servercertificaat (Dit S/MIME certificaat is verlopen).<br /><br />I just would think that receiving an updated-file (with correct dates) would just be the best service.<br /><br /><br />I would also like to know more on the consequences of using Windows certificate and getting MS CryptoAPI &nbsp;(option2).<br /><br /><br />Thanks. <br />
			<i>01 October 2021 14:11:34, <a href="http://www.ritlabs.com/en/forums/">Beatrice Boucher</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52350/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52350/</guid>
			<pubDate>Fri, 01 Oct 2021 14:11:34 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52347/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_nWzGtRvn" href="/en/forums/" bx-tooltip-user-id="97090">Ray Mitchell</a> wrote:<br />After an hour or so I started getting certificate failures on one of the two instances that was previously working with the new certificate, so I had to switch it to the Microsoft certificate too. &nbsp;I&#39;m now just patiently waiting for the third shoe (certificate) to drop. &nbsp;All three instances worked fine together for years with the old certificate.I also have another TB v9.3.4 installation on a totally separate computer. &nbsp;The new certificate worked fine on it for a while but then started failing too so I had to switch to the Microsoft certificate.Does anyone have any idea why this is happening? &nbsp;Is there a reason not to simply use the Microsoft certificate for everything?<br />=============<br />I had no such problems, but it could be due to my first solution being a bit &quot;dirty&quot; and leaving the old certificate in the same Address Book entry. See my post above for a cleaner solution.<br /><br />I don&#39;t know what are the pros and cons of using the Microsoft API, apart from it also working for me. <br />
			<i>01 October 2021 08:13:56, <a href="http://www.ritlabs.com/en/forums/">Miloš Radovanović</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52347/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52347/</guid>
			<pubDate>Fri, 01 Oct 2021 08:13:56 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52346/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_jCX6gK0A" href="/en/forums/" bx-tooltip-user-id="128895">Yann Schlame</a> wrote:<br /><br />Quote Daniel van Rooijen &nbsp;wrote:Yes, I suppose so -- but are we talking about ISRG Root X1 (which had no error message in the log file) or about DST Root CA X3 (which had expired)?<br /><br />The Let&#39;s Encrypt team explain this in their post I linked in the other thread about the same problem: <noindex><a href="https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/" target="_blank" rel="nofollow">https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/</a></noindex> The DST Root CA X3 certificate has expired for good and doesn&#39;t need any updating. It is now obsolete.It appears as if The Bat does not contain/know the newer ISRG Root X1 certificate. This is the one that The Bat needs to import in order for Let&#39;s Encrypt certificates to be correctly validated again.<br />=============<br />Yes, the ISRG Root X1 is the official successor to the now expired DST Root CA X3, that&#39;s why I used it. Importing the ISRG Root X1 .der file into the Address Book entry for DST Root CA X3 is the first thing I tried and it did the job. I can also confirm that creating a separate Address Book entry for ISRG Root X1 and importing the .der file there will also do the trick (of course, also deleting the certificate previously imported to the DST Root CA X3 entry). I guess this is a cleaner solution. <br />
			<i>01 October 2021 08:07:16, <a href="http://www.ritlabs.com/en/forums/">Miloš Radovanović</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52346/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52346/</guid>
			<pubDate>Fri, 01 Oct 2021 08:07:16 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52345/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_G3TSRetP" href="/en/forums/" bx-tooltip-user-id="311">Daniel van Rooijen</a> wrote:<br />Yes, I suppose so -- but are we talking about ISRG Root X1 (which had no error message in the log file) or about DST Root CA X3 (which had expired)?<br /><br />=============<br /><br />The Let&#39;s Encrypt team explain this in their post I linked in the other thread about the same problem:<br /><br /><noindex><a href="https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/" target="_blank" rel="nofollow">https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/</a></noindex><br /><br />The DST Root CA X3 certificate has expired for good and doesn&#39;t need any updating. It is now obsolete.<br /><br />It appears as if The Bat does not contain/know the newer ISRG Root X1 certificate. This is the one that The Bat needs to import in order for Let&#39;s Encrypt certificates to be correctly validated again. <br />
			<i>01 October 2021 06:13:19, <a href="http://www.ritlabs.com/en/forums/">Yann Schlame</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52345/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52345/</guid>
			<pubDate>Fri, 01 Oct 2021 06:13:19 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52344/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Very strange. &nbsp;I&#39;m using TB v9.3.4 and running three simultaneous instances of it on the same computer. &nbsp;Downloading and installing a new certificate solved the problem in two of the instances but not the third. &nbsp;When I switched to the Microsoft certificate the third instance began to work, but would resume failing when I switched back to the new certificate.<br /><br />After an hour or so I started getting certificate failures on one of the two instances that was previously working with the new certificate, so I had to switch it to the Microsoft certificate too. &nbsp;I&#39;m now just patiently waiting for the third shoe (certificate) to drop. &nbsp;All three instances worked fine together for years with the old certificate.<br /><br />I also have another TB v9.3.4 installation on a totally separate computer. &nbsp;The new certificate worked fine on it for a while but then started failing too so I had to switch to the Microsoft certificate.<br /><br />Does anyone have any idea why this is happening? &nbsp;Is there a reason not to simply use the Microsoft certificate for everything? <br />
			<i>01 October 2021 05:12:54, <a href="http://www.ritlabs.com/en/forums/">Ray Mitchell</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52344/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52344/</guid>
			<pubDate>Fri, 01 Oct 2021 05:12:54 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52343/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_kZ5REWw5" href="/en/forums/" bx-tooltip-user-id="128897">Miloš Radovanović</a> wrote:<br />Yes, the devs should definitely include the new certificate. As is, servers that use the Let's Encrypt certificate chain are not supported out-of-the-box.<br />=============<br /> <br />Yes, I suppose so -- but are we talking about ISRG Root X1 (which had no error message in the log file) or about DST Root CA X3 (which had expired)? &nbsp;<br /><br />In line a) of your explanation, you say that ISRG Root X1 must be downloaded but in line B you seem to import it in the address book entry for DST Root CA X3. &nbsp;Could it be that you meant to say in line a) that DST Root CA X3 must be downloaded? That would seem to make more sense to me, but I may well be mistaken. <br />
			<i>01 October 2021 03:52:14, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52343/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52343/</guid>
			<pubDate>Fri, 01 Oct 2021 03:52:14 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52342/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br />2) You may have to temporarily switch The Bat from using its own certificates to using those in Windows. For this, go to Options | S/MIME and TLS and change the first setting there to Microsoft CryptoAPI. <br />=============<br /> I used this option as well, it and resolved the issue. I&#39;ll try the first option when I have more time to be sure of exactly which cert I need.<br /><br />Thanks for the help! <img src="http://www.ritlabs.com/bitrix/images/main/smiles/5/icon_smile.gif" border="0" data-code=":)" data-definition="SD" alt=":)" style="width:16px;height:16px;" title="" class="bx-smile" /><br /><br />Edit: just saw 				 <noindex><a href="https://www.ritlabs.com/en/auth-forums/user/128897/" target="_blank" rel="nofollow">Miloš Radovanović</a></noindex>&#39;s post about it. I&#39;ll do it soon as I can. <br />
			<i>30 September 2021 22:55:42, <a href="http://www.ritlabs.com/en/forums/">cbiweb</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52342/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52342/</guid>
			<pubDate>Thu, 30 Sep 2021 22:55:42 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52341/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Yes, the devs should definitely include the new certificate. As is, servers that use the Let&#39;s Encrypt certificate chain are not supported out-of-the-box. <br />
			<i>30 September 2021 22:54:40, <a href="http://www.ritlabs.com/en/forums/">Miloš Radovanović</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52341/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52341/</guid>
			<pubDate>Thu, 30 Sep 2021 22:54:40 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52340/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Thanks so much, Miloš! Great to hear that it's not a bug. <br /><br />Even so, I have opened a support ticket to notify the developers. Maybe they should include that root certificate in The Bat. <br />
			<i>30 September 2021 22:51:28, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52340/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52340/</guid>
			<pubDate>Thu, 30 Sep 2021 22:51:28 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52339/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			I confirm that the first two possibilities work, and that there is no problem with the Bat&#39;s interpretation.<br /><br />Step-by-step details:<br /><br />1) <br /><br />a) Download ISRG Root X1 .der file from <noindex><a href="https://letsencrypt.org/certificates/" target="_blank" rel="nofollow">https://letsencrypt.org/certificates/</a></noindex><br />b) Go to Tools -&gt; Address Book -&gt; Trusted Root CA -&gt; DST Root CA X3 -&gt; (right click) Properties -&gt; (tab) Certificates -&gt; Import... and import the .der file<br />If Trusted Root CA is not visible in the Address Book, turn on the option from the View menu item.<br /><br />OR<br /><br />2) <br /><br />Switch to Options -&gt; S/MIME and TLS... -&gt; Microsoft CryptoAPI <br />
			<i>30 September 2021 22:46:23, <a href="http://www.ritlabs.com/en/forums/">Miloš Radovanović</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52339/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52339/</guid>
			<pubDate>Thu, 30 Sep 2021 22:46:23 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52338/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_oybqHQrW" href="/en/forums/" bx-tooltip-user-id="128895">Yann Schlame</a> wrote:<br />Awesome! That fixes it for me. Thank you. <img src="http://www.ritlabs.com/bitrix/images/main/smiles/5/icon_smile.gif" border="0" data-code=":)" data-definition="SD" alt=":)" style="width:16px;height:16px;" title="" class="bx-smile" /><br />=============<br /><br />Happy to hear it! Hopefully it's not a bug in the certificate interpretation but simply a missing certificate (or The Bat may just be more strict than others). <br />
			<i>30 September 2021 22:45:18, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52338/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52338/</guid>
			<pubDate>Thu, 30 Sep 2021 22:45:18 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52337/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Further to point 1: <br /><br />In The Bat, certificates are handled through the Address Book. To add a certificate:<br /><br />- Tools | Address Book (F8)<br />- In the address book: View | Certificate Address Books<br />- Select the relevant certificate section (intermediate or root)<br />- Click: File | New | Contact<br />- Go to the Certificates tab and click 'import' to import the file that holds the certificate. <br /><br />As to this specific situation, I don't know which specific certificate has to be imported to fix the chain of trust, but hopefully you guys can figure that out yourselves, and maybe Let's Encrypt's tech support can help you if you send them your error log. <br />
			<i>30 September 2021 22:43:23, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52337/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52337/</guid>
			<pubDate>Thu, 30 Sep 2021 22:43:23 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52336/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_ZWnzBumd" href="/en/forums/" bx-tooltip-user-id="311">Daniel van Rooijen</a> wrote:<br /> You may have to temporarily switch The Bat from using its own certificates to using those in Windows. For this, go to Options | S/MIME and TLS and change the first setting there to Microsoft CryptoAPI.<br />=============<br /><br />Awesome! That fixes it for me. Thank you. <img src="http://www.ritlabs.com/bitrix/images/main/smiles/5/icon_smile.gif" border="0" data-code=":)" data-definition="SD" alt=":)" style="width:16px;height:16px;" title="" class="bx-smile" /><br /><br />Of course I hope The Bat will also receive an update to get rid of the problem altogether, but as a workaround, that seems to do it. <br />
			<i>30 September 2021 22:40:35, <a href="http://www.ritlabs.com/en/forums/">Yann Schlame</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52336/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52336/</guid>
			<pubDate>Thu, 30 Sep 2021 22:40:35 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52335/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			I see three possibilities: <br /><br />1) You may need to add a certificate to the address book so that The Bat will trust it. The company in question, Let's Encrypt, is making its certificates available here: &nbsp;<noindex><a href="https://letsencrypt.org/certificates/" target="_blank" rel="nofollow">https://letsencrypt.org/certificates/</a></noindex> <br /><br />2) You may have to temporarily switch The Bat from using its own certificates to using those in Windows. For this, go to Options | S/MIME and TLS and change the first setting there to Microsoft CryptoAPI.<br /><br />3) Or there is a problem with the Bat's interpretation of the certificate, and the developers have to fix it.<br /><br />ps: User Yann Schlame posted a similar problem report, which I've closed, here: <noindex><a href="https://www.ritlabs.com/en/auth-forums/forum4/topic15457/" target="_blank" rel="nofollow">https://www.ritlabs.com/en/auth-forums/forum4/topic15457/</a></noindex> <br />
			<i>30 September 2021 22:34:42, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52335/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52335/</guid>
			<pubDate>Thu, 30 Sep 2021 22:34:42 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Getting 'certificate expired' message when the certificate is NOT expired.</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15456/message52329/">Getting 'certificate expired' message when the certificate is NOT expired.</a></b> <i>Web host confirms that their certificate is valid</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<div align="center"><span class="bx-font" style="color:#EE1D24">=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=<br />Moderator's note, Oct. 1st 2021: Ritlabs has addressed this issue in a statement that you can find <noindex><a href="https://www.ritlabs.com/en/news/7666/" target="_blank" rel="nofollow">HERE</a></noindex>.<br />=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=</span></div><br /><br />Very suddenly, earlier today, I stopped being able to send or receive email in TheBat! I have two business domains, and this error happens on both:<br /><br /><I>"TLS handshake failure. Invalid server certificate (This certificate has expired)."</I><br /><br />It also happens on two different computers, both with the latest Windows 10 updates. I rebooted both machines just in case, but the issue persists. It&#39;s been that way more than 5 hours at this point.<br /><br />My Web host confirms that their certificate <B>is valid</B>.<br />As a test I set up one of my email accounts in Mozilla Thunderbird, and it works perfectly. So it definitely appears that TheBat! isn&#39;t accepting the certificate for some reason. I am using version 9.4.4 64-bit.<br /><br />Here is the full log error that I get:<br /><br /><span class="bx-font" style="font-family:Courier New"> 2021-09-30, 15:58:32: FETCH - receiving mail messages</span><br /><span class="bx-font" style="font-family:Courier New"> 2021-09-30, 15:58:32: FETCH - Connecting to POP3 server mail.de.opalstack.com on port 995</span><br /><span class="bx-font" style="font-family:Courier New"> 2021-09-30, 15:58:32: FETCH - Initiating TLS handshake</span><br /><span class="bx-font" style="font-family:Courier New">&gt;2021-09-30, 15:58:32: FETCH - Certificate S/N: 035C215C9F515BE5DA337172D779AC9E0632, algorithm: RSA (2048 bits), issued from 9/4/2021 6:42:32 AM to 12/3/2021 6:42:31 AM, for 1 host(s): *.de.opalstack.com.</span><br /><span class="bx-font" style="font-family:Courier New">&gt;2021-09-30, 15:58:32: FETCH - Owner: "*.de.opalstack.com".</span><br /><span class="bx-font" style="font-family:Courier New">&gt;2021-09-30, 15:58:32: FETCH - Issuer: "US", "Let&#39;s Encrypt", "R3". Valid from 9/4/2020 to 9/15/2025 4:00:00 PM.</span><br /><span class="bx-font" style="font-family:Courier New">&gt;2021-09-30, 15:58:32: FETCH - Issuer: "US", "Internet Security Research Group", "ISRG Root X1". Valid from 1/20/2021 7:14:03 PM to 9/30/2024 6:14:03 PM.</span><br /><span class="bx-font" style="font-family:Courier New">&gt;2021-09-30, 15:58:32: FETCH - Root: "Digital Signature Trust Co.", "DST Root CA X3". Valid from 9/30/2000 9:12:19 PM to 9/30/2021 2:01:15 PM. This certificate has expired!</span><br /><span class="bx-font" style="font-family:Courier New">!2021-09-30, 15:58:32: FETCH - TLS handshake failure. Invalid server certificate (This certificate has expired).</span> <br />
			<i>30 September 2021 22:07:43, <a href="http://www.ritlabs.com/en/forums/">cbiweb</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15456/message52329/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15456/message52329/</guid>
			<pubDate>Thu, 30 Sep 2021 22:07:43 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
	</channel>
</rss>
