User Tools

Site Tools


faq:domain_and_web_hosting:why_https_website_showing_ssl_expired_warning

Why am I seeing "SSL Expired" or "Connection is not private" warning when I access to my website or webmail login page?

AfterOffice uses SSL certificates that are issued by Let’s Encrypt for all of our customers' websites and secure webmail login pages. Let's Encrypt has two main root certificate:

  • DST Root CA X3: An older root certificate that are trusted and recognised by older devices (e.g. Windows XP prior to SP3, MacOS below 10.12.1)
  • ISRG Root X1: A newer root certificate that are trusted and recognised by newer devices (e.g. Windows XP SP3 and above, MacOS 10.12.1 and above)

As of Sep 30, 2021, Let's Encrypt has retired and discontinued the use of DST Root CA X3. If you are using an older device – which do not trust/recognize ISRG Root X1 by default – to access your HTTP websites or webmail login page, you will get an SSL certificate expiration warning. Read more: Let's Encrypt DST Root CA X3 Expiration.

To resolve this issue, users are advised to update their device's software/system in order to be compatible with the new root certificate, or, use a newer device with an updated OS/system.

If system upgrade is not available, users who are using the following devices can try to install and trust the new root certificate manually.

Reference: DST Root CA X3 Expiration, ISRG Root X1 Certificate Compatibility

faq/domain_and_web_hosting/why_https_website_showing_ssl_expired_warning.txt · Last modified: 2021/10/12 11:01 by vikki