惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Last Watchdog
The Last Watchdog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Secure Thoughts
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
T
Tor Project blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Google DeepMind News
Google DeepMind News
L
LINUX DO - 最新话题
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Vercel News
Vercel News
Last Week in AI
Last Week in AI
月光博客
月光博客
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Proofpoint News Feed
博客园 - 叶小钗
NISL@THU
NISL@THU
C
Check Point Blog
K
Kaspersky official blog
N
News and Events Feed by Topic
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
Arctic Wolf
T
Threatpost
GbyAI
GbyAI
L
LINUX DO - 热门话题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Privacy & Cybersecurity Law Blog
N
News and Events Feed by Topic
Scott Helme
Scott Helme
P
Privacy International News Feed
The Register - Security
The Register - Security
G
GRAHAM CLULEY
Recorded Future
Recorded Future
Apple Machine Learning Research
Apple Machine Learning Research
C
Cybersecurity and Infrastructure Security Agency CISA
B
Blog
Project Zero
Project Zero
Cyberwarzone
Cyberwarzone
Webroot Blog
Webroot Blog
Microsoft Security Blog
Microsoft Security Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
D
DataBreaches.Net
J
Java Code Geeks
AWS News Blog
AWS News Blog
Help Net Security
Help Net Security
Engineering at Meta
Engineering at Meta
M
MIT News - Artificial intelligence
T
Threat Research - Cisco Blogs
Google DeepMind News
Google DeepMind News

Let's Encrypt Community Support - Latest topics

New Certificate Fails with Unauthorized 403 Seeking Clarity and Consistency on Configuring HTTP-01 challenge for multiple domains Certifiate failing renewal Letsencrypt blocked in Iran Problem with http verification Cyber-attacks from the secondary verification source addresses Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: How will clients handle X2 by X1 cross certificate revocation HTTPS Certificate Renewal and Mixed Content Issues Affecting My Real-Time Morse Code Website Using Let’s Encrypt .conf Files and Nginx along with Certbot Forbidden by policy error generating the let’s encrypt certificate SSL Certificate installed for 1 of 2 domains Certificate apparently not working Certbot 5.6.0 Release Would signing the key authorization with the ACME private key increase security? Lego 5.0.0 Release Certificate renewal incomplete: missing domains beeandlunetrading.com We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved Is using preferred-chain "ISRG Root X2" still a good idea? Crypt::LE --delayed not being honored Expressway certificate renewal error even after upgrading to the latest version Yocto Bitbake install of Certbot luadns fails with 'NoneType' object is not callable Intended audience for "tlsserver" profile Trouble finding Charter Communications as Web Hoster 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU Certbot deploy-hook Obtaining account ID from xmox.nl email server SSL Certificate Expired - pwgroup.plabcapy.com More cultural recognition of HTTPS adoption Certificado certbot Upcoming Let’s Encrypt Profile Changes On May 13 Lets encrypt certificate issued website scam Issues getting certificates for .de zone Certbot-dns-multi for dns-lego fails with request for two domains Will tlssever profile switch to 45 days next week? Certbot script searching Expired certs shut done websites Automatic renewal across multiple systems serving the same domain Account paused – Request to unpause domain exodus.digitalmansa.com Certificate for web theft phucnha.com DNS-PERSIST without spending an Order Certificate Expired, now I can't create a new one Account paused Invalid unpause URL I need to revoke a cert, how do i do this Recommended Certbot Config for 2 certs with same FQDN with different acme servers The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot Cannot load certificate "/etc/letsencrypt/live/laurexplore.fr/fullchain.pem" A small static ACME server to distribute certs Certferry - easy distribution of wildcard LE certificates Permission errors on Let's ENcrypt certificate requests.exceptions.ConnectionError: ('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer')) The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot LetsEncrypt Consultation SSL/TLS certificate Issue ISRG may have received a National Security Letter or FISA Court Order? Deactivating pending authorization Perhaps this domain is at risk group and is blacklisted on the Let's Encrypt side Certificate renewal error Azuracast letsencrypt error Certbot change provider from Sectigo to CertiNext Privacy policy still mentions disabled services Letsencrypt[.]top is squatting on the LE name and acting as a web client Cert renews not working anymore Root Cert Protection and Signing Process for e.g. Intermediates or Cross-Signs of new Roots DNS Challenge failed incorrect TXT value FreeCert: a lightweight ACME management module for shared hosting and cPanel Certbot is rejecting its own specified _acme-challenge value Not able to renew certificates Issue of SSL Certificate fails Today instantly SSL certificate problems CNAME and CAA clarification Issue an SSL certificate Wacs Domain cert generation - test successful but real fails 400 Posh-acme db_error submitting renewal Does Certbot support CNAME challenge? How does CNAME validation work vs DNS-01? Win-Acme Renewal Failing Suddenly with DNS-01 (Dreamhost) My certicate is obsokete Certbot failed to authenticate some domains Possible deliberate publicly admitted violation of subscriber policy by Tom Murphy VII in the form of HTTPV ARI renewal-info Rate Limit Changes? Missing accounturi field in LE dns-persist-01 challenges Problem obtaining a certificate One cert failing to renew - don't know why Dns-persist-01 deployment status and timeline Issue (apparently) after upgrading certbot/ubuntu [nginx] IPv4 OK, IPv6 NOK Expressway ACME Certificate Renewal failing Certbot nginx challenge times out Certbot 5.5.0 Release Error unmarshaling request Try t Self-Host BitWarden - Having Issues Getting a Cert Various problems with three domains cme_registration.reg: Creating... ╷ │ Error: acme: error: 403 :: POST :: https://acme-v02.api.letsencrypt.org/acme/new-acct :: urn:ietf:params:acme:error:unauthorized :: An account with the provided public key exists but is deactivated Iran's internet outage and challenges for renewing letsencrypt certs Running multiple Certbot renewals in parallel — how to bypass the global lock file? Nginx ipv64.net Fritzbox Dietpi DNS-PERSIST-01 and _validation-persist CNAME Just a small certbot script check An easy way to publish dns-persist-01 records Problem finding dns-persist-01 in staging GoDaddy API access policy update
Safari won't trust Let's Encrypt certs
MarionDiMarc · 2026-04-16 · via Let's Encrypt Community Support - Latest topics

April 15, 2026, 7:51pm 1

Domain is www.i2u2.org. Apache 2.4 on Ubuntu 24.04, and I have full SSH access to the server. Certbot 5.5.0.

We have LE certificates on our webservers, and have for some time with few problems. Recently, some users using Safari reported a "This connection is not private" error when trying to use the site. I can confirm four instances of Safari giving this error, including one on iPadOS 18.7.7 that was updated within the last month.

We are serving the full chain of certificates up to the ISRG Root X1 cert. Checking the details on one Safari error shows that the current correct cert is recognized, with correct 'NotBefore' and 'NotAfter' dates, and "Let's Encrypt" is labeled with "Not Trusted" below it.

SSL Labs gives us an "A" overall rating, so I don't think it's a configuration problem. Nothing about the configuration changed recently. The only thing that changed about our DNS recently was that I raised the TTL on the domain from 10 minutes to 1 day a couple of weeks ago.

It seems much like Safari pushed a new update with new root certs that don't trust Let's Encrypt. If that were true, though, I think there would be more info about that on the internet than I'm finding. There are a few similar questions on these forums, but all are older and don't have clear enough resolutions for me to apply.

How can I troubleshoot this?

hebbet April 15, 2026, 7:58pm 2

Do you get the same error here?

1 Like

rmbolger April 15, 2026, 8:08pm 3

Realistically, you need a device exhibiting the problem so you can actually look at the error messages in detail that Safari is presenting and understand why it thinks there's a problem.

3 Likes

MikeMcQ April 15, 2026, 8:17pm 4

Could it be they are using your domain without the www prefix?

Because your cert only includes the www subdomain so will fail without it. It is not technically wrong to omit the registered domain from a website server cert but it is commonly done.

curl -i https://i2u2.org/ 

curl: (60) SSL: no alternative certificate subject name matches target hostname 'i2u2.org'
More details here: https://curl.se/docs/sslcerts.html

3 Likes

No, I don't. At least not on the one device I have (the iPad)

I have that, the iPad I mentioned. I paged through the details, but I didn't see anything that stood out as meaningful. Can you point me toward what I should be looking for?

rmbolger April 15, 2026, 9:03pm 7

I don't have an iOS 18.x device handy at the moment, so I can't give you screenshots. But there should be some form of "Show Details" link on the "This Connection Is Not Private" error. From there, there might be a "view the certificate" link that should theoretically give you a better idea of what the actual error is.

Definitely double check the SAN values compared to the URL being used as @MikeMcQ suggested.

3 Likes

MikeMcQ April 15, 2026, 9:04pm 8

Have you confirmed a URL with www is being used? Do that from the screen that says "This Connection is Not Private" and just touch the domain name in the address box.

If it shows https://i2u2.org then you need to be using https://www.i2u2.org because your cert only has the www subdomain in it.

I walked through that just now on an iPad. It can easily be missed as Safari usually shows the simple form for the domain in the address box. That is why you must touch it to see the actual URL.

Some browsers automatically try various combinations of http and https and maybe Safari recently changed its preferences. I don't know. But, you should check this domain name as it would exactly explain your symptom and also explain why we don't see millions of failures reported :slight_smile:

2 Likes

Are you sending the intermediates?

The Hello world uses the R12 intermediate, while you use the E7 intermediate. Im pretty sure the R12 is already present in Safari per default since it have existed for a pretty long period now.

If the E7 intermediate is not sent, you will get a "untrusted" on "Let's encrypt" since the leaf certificate will apper to be "self-signed" (since it can't see the certificate in-between).

You need to point your server to the fullchain.pem file for this to work.

I know safari can be picky with WHICH ORDER the certificates are sent in, so try swapping the leaf certificate and the intermediate in fullchain.pem so they are served in the opposite order.

dextercd April 15, 2026, 10:57pm 10

Chrome and Firefox will, upon encountering a certificate domain mismatch error, check if the domain would match the certificate after removing or adding www. and load the replacement URL if so.

As far as I can tell, there's no such code inside WebKit. Opening the non-www URL in a WebKit browser results in a certificate error, while Chrome/Firefox automatically tries the www variant (you can still see the failed request in the dev tools though).

Chromium: common_name_mismatch_handler.cc:117
Firefox: nsDocShell.cpp:6045

3 Likes

You can often debug mobile/ipad safari more easily by connecting your desktop safari dev tools to the mobile safari instance (with the device connected via USB). Debug Websites on iPhone Safari in 2026 | BrowserStack

I can't remember if you need xcode configured for the device as debug or not.

3 Likes

There's a good chance that's it. I do see different behavior between the two on the iPad. I can't explain why the problem is just now showing up, though, since I haven't changed anything lately.

I'll re-issue the cert to cover both forms of the URL later today and report back.

1 Like