<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>www.ritlabs.com [Topic: Let's Encrypt Certificate throws Expired error]</title>
		<link>http://www.ritlabs.com</link>
		<description>New posts in Let's Encrypt Certificate throws Expired error of  forum at www.ritlabs.com [www.ritlabs.com]</description>
		<language>en</language>
		<docs>http://backend.userland.com/rss2</docs>
		<lastBuildDateTag>Thu, 30 Sep 2021 22:27:43 +0300</lastBuildDateTag>		<item>
			<title>Let's Encrypt Certificate throws Expired error</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15457/message52334/">Let's Encrypt Certificate throws Expired error</a></b> <i>DST Root CA X3 expired today and seems to cause The Bat to fail the certficate check</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Let's continue this discussion here, where user Cbiweb posted the same problem just before you did:<br /><br /><noindex><a href="https://www.ritlabs.com/en/auth-forums/forum4/topic15456/" target="_blank" rel="nofollow">https://www.ritlabs.com/en/auth-forums/forum4/topic15456/</a></noindex> <br />
			<i>30 September 2021 22:27:43, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15457/message52334/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15457/message52334/</guid>
			<pubDate>Thu, 30 Sep 2021 22:27:43 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Let's Encrypt Certificate throws Expired error</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15457/message52333/">Let's Encrypt Certificate throws Expired error</a></b> <i>DST Root CA X3 expired today and seems to cause The Bat to fail the certficate check</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br /><a class="blog-p-user-name" id="bp_QeOhXVwq" href="/en/forums/" bx-tooltip-user-id="92930">cbiweb</a> wrote:<br />I just posted about this as well. Hope it gets resolved quickly.<br />=============<br /><br />Haha, yeah, just saw your post after I hit &quot;Send&quot; on mine. <img src="http://www.ritlabs.com/bitrix/images/main/smiles/5/icon_wink.gif" border="0" data-code=";)" data-definition="SD" alt=";)" style="width:16px;height:16px;" title="" class="bx-smile" /> <br />
			<i>30 September 2021 22:27:10, <a href="http://www.ritlabs.com/en/forums/">Yann Schlame</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15457/message52333/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15457/message52333/</guid>
			<pubDate>Thu, 30 Sep 2021 22:27:10 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Let's Encrypt Certificate throws Expired error</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15457/message52332/">Let's Encrypt Certificate throws Expired error</a></b> <i>DST Root CA X3 expired today and seems to cause The Bat to fail the certficate check</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			I just posted about this a few minutes before you as well. Hope it gets resolved quickly. <br />
			<i>30 September 2021 22:25:37, <a href="http://www.ritlabs.com/en/forums/">cbiweb</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15457/message52332/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15457/message52332/</guid>
			<pubDate>Thu, 30 Sep 2021 22:25:37 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>Let's Encrypt Certificate throws Expired error</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic15457/message52330/">Let's Encrypt Certificate throws Expired error</a></b> <i>DST Root CA X3 expired today and seems to cause The Bat to fail the certficate check</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<div align="center"><span class="bx-font" style="color:#EE1D24">=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=<br />Moderator's note, Oct. 1st 2021: Ritlabs has addressed this issue in a statement that you can find <noindex><a href="https://www.ritlabs.com/en/news/7666/" target="_blank" rel="nofollow">HERE</a></noindex>.<br />=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=</span></div><br /><br />I run a several mailservers with Let's Encrypt certificates (*). This afternoon, The Bat Version 9.4.4 (64-bit) began showing an error for the mailservers' certificates.<br /><br />Error fr om an internal IMAP server:<br /><br /><br />====quote====<br /> 30.09.2021, 20:02:46: IMAP &nbsp;- Connecting to IMAP server mail.int.example.org on port 993<br /> 30.09.2021, 20:02:46: IMAP &nbsp;- Initiating TLS handshake<br />&gt;30.09.2021, 20:02:46: IMAP &nbsp;- Certificate S/N: 03A5*****, algorithm: RSA (2048 bits), issued from 9/26/2021 3:51:34 AM to 12/25/2021 3:51:33 AM, for 2 host(s): mail.int.example.org, <noindex><a href="http://www.mail.int.example.org" target="_blank" rel="nofollow">www.mail.int.example.org</a></noindex>.<br />&gt;30.09.2021, 20:02:46: IMAP &nbsp;- Owner: "mail.int.example.org".<br />&gt;30.09.2021, 20:02:46: IMAP &nbsp;- Issuer: "US", "Let's Encrypt", "R3". Valid from 9/4/2020 to 9/15/2025 4:00:00 PM.<br />&gt;30.09.2021, 20:02:46: IMAP &nbsp;- Issuer: "US", "Internet Security Research Group", "ISRG Root X1". Valid from 1/20/2021 7:14:03 PM to 9/30/2024 6:14:03 PM.<br />&gt;30.09.2021, 20:02:46: IMAP &nbsp;- Root: "Digital Signature Trust Co.", "DST Root CA X3". Valid from 9/30/2000 9:12:19 PM to 9/30/2021 2:01:15 PM. <B>This certificate has expired!</B><br />!30.09.2021, 20:02:46: IMAP &nbsp;- TLS handshake failure. Invalid server certificate (This certificate has expired).<br /><br />=============<br /><br />Error from a public POP3 server:<br /><br /><br />====quote====<br /> 30.09.2021, 21:00:08: FETCH - receiving mail messages<br /> 30.09.2021, 21:00:08: FETCH - Connecting to POP3 server mail.example.org on port 995<br /> 30.09.2021, 21:00:08: FETCH - Initiating TLS handshake<br />&gt;30.09.2021, 21:00:08: FETCH - Certificate S/N: 039D****, algorithm: RSA (2048 bits), issued from 7/19/2021 7:45:19 AM to 10/17/2021 7:45:17 AM, for 1 host(s): mail.example.org.<br />&gt;30.09.2021, 21:00:08: FETCH - Owner: "mail.example.org".<br />&gt;30.09.2021, 21:00:08: FETCH - Issuer: "US", "Let's Encrypt", "R3". Valid from 9/4/2020 to 9/15/2025 4:00:00 PM.<br />&gt;30.09.2021, 21:00:08: FETCH - Issuer: "US", "Internet Security Research Group", "ISRG Root X1". Valid from 1/20/2021 7:14:03 PM to 9/30/2024 6:14:03 PM.<br />&gt;30.09.2021, 21:00:08: FETCH - Root: "Digital Signature Trust Co.", "DST Root CA X3". Valid from 9/30/2000 9:12:19 PM to 9/30/2021 2:01:15 PM. <B>This certificate has expired!</B><br />!30.09.2021, 21:00:08: FETCH - TLS handshake failure. Invalid server certificate (This certificate has expired).<br /><br />=============<br /><br />Today, Let's Encrypt's cross-signed certificate DST Root CA X3 expired, which had been announced in advance, see: <noindex><a href="https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/" target="_blank" rel="nofollow">https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/</a></noindex><br /><br />Thunderbird clients on similar PCs connect to the internal IMAP server with no issues.<br /><br />My operating system on the affected PC is: Windows 10 Home, Version 2004, Build 19041.1165<br /><br />Since The Bat was able to connect to the mailserver without issues earlier this afternoon, I suspect the expired cross-signing certificate is the one causing the problem, as highlighted in the error message. According to Let's Encrypt's announcement, the Let's Encrypt Root certificate should still be considered valid, meaning that the entire certificate should be valid.<br /><br />I can't tell wh ere the problem lies within the Certficate Chain, and would be grateful for pointers on how to fix the problem for my installation of The Bat.<br /><br /><br />(*) I have HTTP hosts set up with the same hostnames as the internal and public mailservers; these HTTP hosts retrieve and update their Let's Encrypt certificates through the normal renewal procedure. A bunch of custom shell scripts then copy the certificates into the postfix and dovecot config directories and restart the mailserver programs after every certificate update. <br />
			<i>30 September 2021 22:12:59, <a href="http://www.ritlabs.com/en/forums/">Yann Schlame</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic15457/message52330/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic15457/message52330/</guid>
			<pubDate>Thu, 30 Sep 2021 22:12:59 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
	</channel>
</rss>
