# Let's encrypt root certificate change

**URL:** <https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866>\
**Category:** General\
**Created:** [18 May 2021 15:52 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866 "2021-05-18T15:52:47Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [18 May 2021 15:52 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/1 "2021-05-18T15:52:47Z")

</div>

Anyone know if the [changes described here](https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/) are likely to impact on node-RED users?  
I see that it makes particular reference to api's & IoT devices, but I don't really understand the implications...

---

<div class="post-metadata">

**Author:** ![Ranki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ranki/32/41282_2.png) [@Ranki](https://discourse.nodered.org/u/Ranki)\
**Post date:** [18 May 2021 16:12 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/2 "2021-05-18T16:12:14Z")

</div>

Hello @Paul-Reed,

Trying to make a long story short:  
there is at least one authority, which is trusted by everyone (_in real there are more than one_). The certificates, which are trusted/ created by this authority are therefore trusted by every client.

If this organization now has to change his name (root certificate), everyone needs to trust the authority with the new name. Some clients are not able to make the switch to the new name (root certificate) and therefore new certificates, which are trusted/ created by the organization with the new name are not trusted by the older clients (as they do not know the new name).

So, coming back to node-red:  
Every client, which is connecting to a secured server (like the server hosting node-red) via https might be affected. But I guess node-red will not be effected as you usually access node-red via browser or maybe webhook.

What might be more interesting: **mosquito**  
If you are accessing mosquito via https and the IoT devices need to access the server via https, you have to clarify, if they are trusting the new root certificate (organization with the new name).

I hope I summarized everything correct and understandable.

Cheers  
Ranki

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 May 2021 16:52 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/3 "2021-05-18T16:52:52Z")

</div>

I would guess that it might affect anything that doesn't update its valid root certificate store.

Thankfully these issues are now few and far between. I would think that things like Mosquitto will be using 3rd-party TLS libraries which will reference an updatable store whether the credential store on Windows or the root certificate list on Linux (probably via OpenSSL). So as long as you are using an Operating System that is still under support, you should be fine. Older IoT devices that support TLS are few and far between anyway so probably not a problem for the majority of people.

Things like old routers or NAS's not receiving updates could also have issues however they are probably not using LE anyway so no problem there.

Node-RED itself shouldn't therefore have an issue unless you run it on an ancient Linux device where you've not updated the OS in a long time. If you are in that situation, I strongly recommend a fresh build.

---

<div class="post-metadata">

**Author:** ![Ranki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ranki/32/41282_2.png) [@Ranki](https://discourse.nodered.org/u/Ranki)\
**Post date:** [18 May 2021 17:01 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/4 "2021-05-18T17:01:38Z")

</div>

Hello @TotallyInformation,

Just for my information:  
I think the problems can only occur on client side, if they do not have the new root certificates, because they do not know, if they can trust. I think the server (e.g. hosting node-red), which is providing a certificate to the client does not need to have the corresponding root certificates in his storage. Am I right?

Cheers  
Ranki

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [18 May 2021 18:06 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/5 "2021-05-18T18:06:49Z")

</div>

Hey Paul,  
You can also have a look ar their [certificate chain](https://letsencrypt.org/certificates/), to see to which root certificate your server certificate belongs.  
Recently @geoffreydemaagd had an issue with my node-red-contrib-letsencrypt node. Reasen appeared to be that I store both the server certificate and the Letsencrypt intermediate certificate are stored into the cert.pem file. I should have a look whether clients with a new/old root certificate would run into troubles, due to an incomplete chain...

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [18 May 2021 18:33 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/6 "2021-05-18T18:33:21Z")

</div>

> [@BartButenaers](#):
>
> both the server certificate and the Letsencrypt intermediate certificate are stored into the cert.pem file. I should have a look whether clients with a new/old root certificate would run into troubles, due to an incomplete chain...

Yes, I had similar problems about 18 months ago, [so I always advise users](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606/58) to use the `fullchain.pem` certificate instead of the `cert.pem` to complete the chain.  
The Letsencrypt Leader - Juergen Auer, said why this was necessary (for node-RED users) [in this thread.](https://community.letsencrypt.org/t/letsencrypt-chain-pem-or-trusted-root-list-cert/105921/10)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 May 2021 19:44 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/7 "2021-05-18T19:44:29Z")

</div>

> [@Paul-Reed](#):
>
> Yes, I had similar problems about 18 months ago, [so I always advise users](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606/58) to use the `fullchain.pem` certificate instead of the `cert.pem` to complete the chain.

I'd forgotten about that but yes I also always use the fullchain.

> [@Ranki](#):
>
> Am I right?

I think you are right but don't forget that the client can be on the server as well as the server 😀

---

<div class="post-metadata">

**Author:** ![Ranki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ranki/32/41282_2.png) [@Ranki](https://discourse.nodered.org/u/Ranki)\
**Post date:** [18 May 2021 19:53 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/8 "2021-05-18T19:53:00Z")

</div>

> [@TotallyInformation](#):
>
> I think you are right but don't forget that the client can be on the server as well as the server

Good point!

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 May 2021 19:55 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/9 "2021-05-18T19:55:35Z")

</div>

To be honest, I hadn't even thought about a desktop/mobile client because if you are using one of those that isn't being updated, you have much bigger problems!

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [18 May 2021 21:02 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/10 "2021-05-18T21:02:51Z")

</div>

> [@BartButenaers](#):
>
> an issue with my node-red-contrib-letsencrypt node

This is the certificate chain that is setup by my letsencrypt node:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/e/4e8c59cc2afc4794bd6a59a7e868efc1f396e11d.png)

So yes indeed, I hope that my browsers (Android and Windows) will have the new root certificate in september. Of course I can always trust it myself temporarily...

I only use it for my remote connection via a browser to my Node-RED system. Not for inter-server communication...

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [18 May 2021 21:28 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/11 "2021-05-18T21:28:18Z")

</div>

Same here [using certbot](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606)

![cert](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/0/b01c1fe7a89b305e7129ad4d5f2218ffc8c07b81.jpeg)

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [18 May 2021 21:30 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/12 "2021-05-18T21:30:00Z")

</div>

Seems you have an extra level "ISRG Root X1" ....

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [18 May 2021 21:36 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/13 "2021-05-18T21:36:14Z")

</div>

Your chain goes via 1-2-3 while mine goes directly via 4-5:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/9/c9e6cd9ced78dfebae9d35b02127dfc3c8bad71f.png)

Not in the mood for digging further into this tonight 😉

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [18 May 2021 21:51 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/14 "2021-05-18T21:51:46Z")

</div>

> [@BartButenaers](#):
>
> Your chain goes via 1-2-3 while mine goes directly via 4-5:

I'm using your letsencrypt node in one of my sites, and see the same certification path as you (4-5).  
But....  
Just requested a new certificate, and it's now 1-2-3  
So maybe it's a change made by letsencrypt??

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [21 May 2021 07:42 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/15 "2021-05-21T07:42:37Z")

</div>

@BartButenaers did you try requesting a new certificate, as in my last post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [20 July 2021 07:42 UTC](https://discourse.nodered.org/t/lets-encrypt-root-certificate-change/45866/16 "2021-07-20T07:42:55Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
