I guess the part I'm confused about is
-Domain TLS, which includes the email services on the machine, failed, as that service does not allow the installation of invalid certificates. This caused users to receive an SSL error when connecting to the mail server as they would have been presented with the hostname SSL instead of the domain SSL.
What certificate in the chain was considered invalid? And what determines validity?
When issuing a Let's Encrypt certificate, the certificate for the domain is valid - yes?
ISRG Root X1 (expires September 15, 2025) is valid - yes?
DST Root CA X3 (expires September 30, 2024) is valid - yes?
So why isn't that being installed?
-Domain TLS, which includes the email services on the machine, failed, as that service does not allow the installation of invalid certificates. This caused users to receive an SSL error when connecting to the mail server as they would have been presented with the hostname SSL instead of the domain SSL.
What certificate in the chain was considered invalid? And what determines validity?
When issuing a Let's Encrypt certificate, the certificate for the domain is valid - yes?
ISRG Root X1 (expires September 15, 2025) is valid - yes?
DST Root CA X3 (expires September 30, 2024) is valid - yes?
So why isn't that being installed?