<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Certificate error accessing site due to expired cert in trust chain]]></title><description><![CDATA[<p dir="auto">Our staff are experincing issues accessing <a href="https://windy.com" rel="nofollow ugc">https://windy.com</a> due to an expired certificate in the trust chain which is not playing well with Fortigate firewalls in certain configurations. This prevents staff from accessing the site at all with the following error</p>
<p dir="auto"><img src="/assets/uploads/files/1633399132380-5c8f2144-47f6-4237-b585-e1f64204bcfb-image.png" alt="5c8f2144-47f6-4237-b585-e1f64204bcfb-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">This is because the <a href="http://windy.com" rel="nofollow ugc">windy.com</a> R3 certificate has a expired cert in its trust chain</p>
<p dir="auto"><img src="/assets/uploads/files/1633398142024-12e07bbb-1fdd-449a-b4da-655a47d05a9b-image.png" alt="12e07bbb-1fdd-449a-b4da-655a47d05a9b-image.png" class=" img-fluid img-markdown" /> - <a href="https://www.ssllabs.com/ssltest/analyze.html?d=www.windy.com&amp;s=143.204.128.52" rel="nofollow ugc">https://www.ssllabs.com/ssltest/analyze.html?d=www.windy.com&amp;s=143.204.128.52</a></p>
<p dir="auto">The Fortigate issue is documented here - <a href="https://www.fortinet.com/blog/psirt-blogs/fortinet-and-expiring-lets-encrypt-certificates" rel="nofollow ugc">https://www.fortinet.com/blog/psirt-blogs/fortinet-and-expiring-lets-encrypt-certificates</a></p>
<p dir="auto">and the expected certificate expiry is documented here - <a href="https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/" rel="nofollow ugc">https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/</a></p>
<p dir="auto">The ultimate fix is for the <a href="http://windy.com" rel="nofollow ugc">windy.com</a> certificate to be renewed without the expired cert in the trust chain. Can this please be arranged?</p>
]]></description><link>https://community.windy.com/topic/18081/certificate-error-accessing-site-due-to-expired-cert-in-trust-chain</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Jul 2026 15:09:55 GMT</lastBuildDate><atom:link href="https://community.windy.com/topic/18081.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 05 Oct 2021 02:06:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Certificate error accessing site due to expired cert in trust chain on Thu, 21 Oct 2021 07:50:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/meteo2021" aria-label="Profile: meteo2021">@<bdi>meteo2021</bdi></a> Hello, you may have a problem if you have an older operating system (Windows &lt; XP SP3 or macOS &lt; 10.12.1). Did you try the Mozilla browser 93.0.?</p>
]]></description><link>https://community.windy.com/post/90308</link><guid isPermaLink="true">https://community.windy.com/post/90308</guid><dc:creator><![CDATA[Korina]]></dc:creator><pubDate>Thu, 21 Oct 2021 07:50:57 GMT</pubDate></item><item><title><![CDATA[Reply to Certificate error accessing site due to expired cert in trust chain on Wed, 20 Oct 2021 19:27:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/korina" aria-label="Profile: korina">@<bdi>korina</bdi></a> Okay, is the latest version of Google Chrome Version 95.0.4638.54 (Official Build) (64-bit) an older browser and is there a possibility to access it through this browser?</p>
]]></description><link>https://community.windy.com/post/90272</link><guid isPermaLink="true">https://community.windy.com/post/90272</guid><dc:creator><![CDATA[meteo2021]]></dc:creator><pubDate>Wed, 20 Oct 2021 19:27:30 GMT</pubDate></item><item><title><![CDATA[Reply to Certificate error accessing site due to expired cert in trust chain on Fri, 08 Oct 2021 06:00:02 GMT]]></title><description><![CDATA[<p dir="auto">@brian-voller Hello, as I mentioned, we stopped supporting old root certificates on older browsers -  <a href="https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/" rel="nofollow ugc">https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/</a></p>
<p dir="auto">We can recommend to use updated OS. Or if you still have issues, use the latest Mozilla browser 93.0., where you should not have any problems, since Mozilla downloads certificates on its own and does not rely on OS.</p>
]]></description><link>https://community.windy.com/post/89200</link><guid isPermaLink="true">https://community.windy.com/post/89200</guid><dc:creator><![CDATA[Korina]]></dc:creator><pubDate>Fri, 08 Oct 2021 06:00:02 GMT</pubDate></item><item><title><![CDATA[Reply to Certificate error accessing site due to expired cert in trust chain on Wed, 06 Oct 2021 18:55:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/korina" aria-label="Profile: korina">@<bdi>korina</bdi></a> Yes. The issue for us is that <a href="http://windy.com" rel="nofollow ugc">windy.com</a> is using a certificate with an EXPIRED certificate in its trust chain as shown above.</p>
]]></description><link>https://community.windy.com/post/89058</link><guid isPermaLink="true">https://community.windy.com/post/89058</guid><dc:creator><![CDATA[brian.voller]]></dc:creator><pubDate>Wed, 06 Oct 2021 18:55:03 GMT</pubDate></item><item><title><![CDATA[Reply to Certificate error accessing site due to expired cert in trust chain on Wed, 06 Oct 2021 06:10:09 GMT]]></title><description><![CDATA[<p dir="auto">@brian-voller Hello, did you clear your cache please?</p>
]]></description><link>https://community.windy.com/post/89004</link><guid isPermaLink="true">https://community.windy.com/post/89004</guid><dc:creator><![CDATA[Korina]]></dc:creator><pubDate>Wed, 06 Oct 2021 06:10:09 GMT</pubDate></item><item><title><![CDATA[Reply to Certificate error accessing site due to expired cert in trust chain on Tue, 05 Oct 2021 21:24:04 GMT]]></title><description><![CDATA[<p dir="auto">This issue IS occurring in modern browsers<br />
e.g.<br />
Chrome 94.0.4606.71<br />
Edge 94.0.992.38</p>
]]></description><link>https://community.windy.com/post/88979</link><guid isPermaLink="true">https://community.windy.com/post/88979</guid><dc:creator><![CDATA[brian.voller]]></dc:creator><pubDate>Tue, 05 Oct 2021 21:24:04 GMT</pubDate></item><item><title><![CDATA[Reply to Certificate error accessing site due to expired cert in trust chain on Tue, 05 Oct 2021 07:11:00 GMT]]></title><description><![CDATA[<p dir="auto">@brian-voller Hello, please see the related <a href="https://community.windy.com/topic/18050/unable-to-establish-a-secure-connection-outdated-certificate?_=1633417691673">post</a>.</p>
<p dir="auto">We have stopped supporting certificates for older browsers, more information <a href="https://techcrunch.com/2021/09/21/lets-encrypt-root-expiry/" rel="nofollow ugc">here</a>. You will need to upgrade your browser.</p>
]]></description><link>https://community.windy.com/post/88911</link><guid isPermaLink="true">https://community.windy.com/post/88911</guid><dc:creator><![CDATA[Korina]]></dc:creator><pubDate>Tue, 05 Oct 2021 07:11:00 GMT</pubDate></item></channel></rss>