Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Lets Encrypt : option to choose the chain, certficate is not valid anymore on older devices #2565

Closed
pergolafabio opened this issue Jun 29, 2022 · 7 comments

Comments

@pergolafabio
Copy link

Describe the issue you are experiencing

Hi, seems the Lets Encrypt addon is hardcoded to use this chain :

--preferred-chain "ISRG Root X1"

--preferred-chain "ISRG Root X1"

According to this thread, its the alternate chain

https://community.letsencrypt.org/t/production-chain-changes/150739

Is it possible to make an config option, so we can choose the chain type? seems the "X1" chain is not supported anymore on older android types

Thnx in advance

What type of installation are you running?

Home Assistant OS

Which operating system are you running on?

Home Assistant Operating System

Which add-on are you reporting an issue with?

Let's Encrypt

What is the version of the add-on?

4.12.5

Steps to reproduce the issue

No steps to reproduce

Anything in the Supervisor logs that might be useful for us?

No response

Anything in the add-on logs that might be useful for us?

No response

Additional information

No response

@mdegat01
Copy link
Contributor

mdegat01 commented Jun 30, 2022

Platforms that trust ISRG Root X1:

...

Platforms that trust DST Root CA X3 but not ISRG Root X1 - Notice no version of android is in this list

Known Incompatible:

...

  • Android < v2.3.6

If your android version is older then 2.3.6 then according to Let's Encrypt nothing will make it work. Except possibly switching to firefox as your mobile browser. If your android version is >= 2.3.6 then you should be using ISRG Root X1.

What is your android version and what actually is the issue you're facing? Did you confirm that changing the chain fixes it by running Let's Encrypt manually on some other system? If so please share the chain you used.

I'm not opposed to a config option but I need to know why and that it will actually help. Btw I think the post you linked is in agreement with what I posted above (I would hope so since my links and quotes come directly from the Let's Encrypt website) it's just confusingly worded. When they say "Android compatibility of the longer chain" I believe they are referring to Android versions < 2.3.6. And to my knowledge neither the post nor what I linked presents any viable options for Android devices that out of date at this point other then (possibly) switching to firefox.

@pergolafabio
Copy link
Author

Hi, thnx for the feedback, my wall android devices are using 5.0

here is some more info and screens:

https://community.home-assistant.io/t/make-ha-use-1-2-tls/434804

@pergolafabio
Copy link
Author

hey @mdegat01 , did you already create a PR for this?

@github-actions
Copy link

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale label Aug 28, 2022
@pergolafabio
Copy link
Author

Unstale

@github-actions github-actions bot removed the stale label Aug 28, 2022
@github-actions
Copy link

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale label Sep 27, 2022
@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Oct 4, 2022
@rrooggiieerr
Copy link

rrooggiieerr commented Dec 8, 2022

I'd also like to opt for an option to chose the chain as my wall tablet with old Android 5.0.1 is now unable to connect to HA when I enable SSL, while using cain "DST Root CA X3" should solve this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants