7 Messages

Friday, July 26th, 2024

Closed

the certificates in the pop3 server certificate chain file are not in the correct order

Last Friday, 7/19, I was alerted there was a change in the pop3 995 TLS Certificates and there was the following issue:

    No certificate issuer found
Trust / do not trust?

I elected not to trust at the time.  Hoped it would be resolved quickly.

The problem still exists.

I manually downloaded the pop3 995 server certificate chain (pem file).

I verified the chain and the following results were similar to the warning I saw on Friday:

    Chain verification output: Not verified. The certificate is NOT trusted. The certificate issuer is unknown.
The smtp 587 TLS Certificates had no changes and no issues.

I manually downloaded the smtp 587 server certificate chain (pem file).

I verified the chain and there were no issues.

What is the difference between the two files?

The order of the certificates.

I reordered the certificates in the pop3 995 server certificate chain file to reflect the order of the certificates in the smtp 587 server certificate chain file and manually verified:

    Chain verification output: Verified. The certificate is trusted.

If the pop3 995 server certificate chain was fixed on the server end would the issue I am seeing be resolved at my end?  I think so, but this has been a learning curve.

 

Oldest First
Selected Oldest First
No Responses!
forum icon

New to the Community?

Start Here