# Fix for "Certificate has expired" error with Joplin Cloud and self-hosted sync targets

**URL:** <https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638>\
**Category:** News\
**Created:** [30 September 2021 16:35 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638 "2021-09-30T16:35:36Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 16:35 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/1 "2021-09-30T16:35:36Z")

</div>

**Updates:**

- The issue has been resolved in Joplin Cloud, so if you had the "Ignore TLS certificate errors" option enabled, don't forget to switch it off as it is not secure.

- If you are self hosting and are having troubles with this bug, please give a try to the latest pre-release, which includes a permanent fix: [Pre-release v2.5 is now available (Updated 2 Oct)](https://discourse.joplinapp.org/t/pre-release-v2-5-is-now-available-updated-2-oct/20702)

* * *

Some of you might be experiencing an error "Certificate has expired" when synchronising with Joplin Cloud (and possibly other services) when using the desktop application.

This is due to Let's Encrypt root certificate that expired on 30 September, and the new method they are using is not compatible with the Joplin desktop application.

This actually affects thousands of applications, not just Joplin, so various solutions are being considered right now and hopefully a fix will be available relatively soon.

For now, as a workaround, you can simply check " **Ignore TLS certificate errors**" in **Configuration \> Synchronisation \> Advanced Options**

I will let you know as soon as a fix is available so that you can clear that option.

More info:

- [Issue with Electron and expired root](https://community.letsencrypt.org/t/issues-with-electron-and-expired-root/160991) on Let's Encrypt

- [Let's Encrypt root CA isn't working properly](https://github.com/electron/electron/issues/31212) on Electron GitHub repository

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 16:35 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/2 "2021-09-30T16:35:50Z")

</div>



---

<div class="post-metadata">

**Author:** ![wazabees](https://avatars.discourse-cdn.com/v4/letter/w/6a8cbe/32.png) [@wazabees](https://discourse.joplinapp.org/u/wazabees)\
**Post date:** [30 September 2021 16:38 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/3 "2021-09-30T16:38:44Z")

</div>

And for those of you using Joplin CLI as well, disable it there too. 😉

`joplin config net.ignoreTlsErrors true`

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 17:09 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/4 "2021-09-30T17:09:57Z")

</div>

**Update:** I have implemented a temporary fix on Joplin Cloud which should solve the issue for now. If you're having still some issues please let me know. An updated desktop app will be available later on with a more permanent fix.

---

<div class="post-metadata">

**Author:** ![benmordecai](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@benmordecai](https://discourse.joplinapp.org/u/benmordecai)\
**Post date:** [30 September 2021 17:19 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/5 "2021-09-30T17:19:45Z")

</div>

I am having issues with Nextcloud sync. I self-host the nextcloud and it shows a valid cert when I check from the web interface.

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 17:21 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/6 "2021-09-30T17:21:26Z")

</div>

This worked for Joplin Cloud, and the same method could be applied on your server probably:

[[Bug]: Let's Encrypt root CA isn't working properly · Issue #31212 · electron/electron · GitHub](https://github.com/electron/electron/issues/31212#issuecomment-931486784)

---

<div class="post-metadata">

**Author:** ![paperboy](https://avatars.discourse-cdn.com/v4/letter/p/54ee81/32.png) [@paperboy](https://discourse.joplinapp.org/u/paperboy)\
**Post date:** [30 September 2021 22:55 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/7 "2021-09-30T22:55:53Z")

</div>

The workaround works, but does it present a security issue? Thank you.

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 23:25 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/8 "2021-09-30T23:25:00Z")

</div>

No it doesn't, it's still a valid certificate.

---

<div class="post-metadata">

**Author:** ![vmsman](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/vmsman/32/10417_2.png) [@vmsman](https://discourse.joplinapp.org/u/vmsman)\
**Post date:** [1 October 2021 00:37 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/9 "2021-10-01T00:37:16Z")

</div>

Thank you, thank you!!! Invaluable help. I was tearing my hair out with Joplin desktop having the certificate error and I kept thinking it was the cert on my nextcloud.

---

<div class="post-metadata">

**Author:** ![cnburke](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/cnburke/32/3555_2.png) [@cnburke](https://discourse.joplinapp.org/u/cnburke)\
**Post date:** [1 October 2021 03:15 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/10 "2021-10-01T03:15:53Z")

</div>

For those running their own Joplin Server using apache and certbot to manage the certificate generation, the following fixes the issue:

```auto
sudo certbot certonly --preferred-chain "ISRG Root X1" --apache

```

(Note this is a suggested reply in the link posted above by @laurent)

The joplin server setup I'm using is is based off of this thread [Guide for Joplin-Server on Raspberry Pi](https://discourse.joplinapp.org/t/guide-for-joplin-server-on-raspberry-pi/14702) (thanks to @MrKanister)

---

<div class="post-metadata">

**Author:** ![AdminByTheBay](https://avatars.discourse-cdn.com/v4/letter/a/b77776/32.png) [@AdminByTheBay](https://discourse.joplinapp.org/u/AdminByTheBay)\
**Post date:** [1 October 2021 12:48 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/11 "2021-10-01T12:48:10Z")

</div>

In case others are having issues with `--preferred-chain` not being a recognized flag on Ubuntu 18.04 LTS, following this comment worked for me: [[Bug]: Let's Encrypt root CA isn't working properly · Issue #31212 · electron/electron · GitHub](https://github.com/electron/electron/issues/31212#issuecomment-931658021)

---

<div class="post-metadata">

**Author:** ![filupmarley](https://avatars.discourse-cdn.com/v4/letter/f/13edae/32.png) [@filupmarley](https://discourse.joplinapp.org/u/filupmarley)\
**Post date:** [2 October 2021 01:09 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/13 "2021-10-02T01:09:22Z")

</div>

Thanks laurent! This fixed my desktop issue on desktop.

---

<div class="post-metadata">

**Author:** ![jannes](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@jannes](https://discourse.joplinapp.org/u/jannes)\
**Post date:** [2 October 2021 06:22 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/14 "2021-10-02T06:22:18Z")

</div>

The option is called "Ignore TLS certificate errors".  
So, now anyone could self-sign a certificate for your synchronization target and pretend to be them. How is that not a security issue?

There is another option, "Custom TLS certificates", isn't it better to download the certificate of your sync target and import it here?

---

<div class="post-metadata">

**Author:** ![Manchineel](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/manchineel/32/10723_2.png) [@Manchineel](https://discourse.joplinapp.org/u/Manchineel)\
**Post date:** [2 October 2021 07:53 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/15 "2021-10-02T07:53:24Z")

</div>

> [@jannes](#):
>
> So, now anyone could self-sign a certificate for your synchronization target and pretend to be them. How is that not a security issue?

It is. This is a temporary, stopgap solution.

---

<div class="post-metadata">

**Author:** ![Senskr](https://avatars.discourse-cdn.com/v4/letter/s/65b543/32.png) [@Senskr](https://discourse.joplinapp.org/u/Senskr)\
**Post date:** [2 October 2021 09:48 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/16 "2021-10-02T09:48:29Z")

</div>

If anyone uses an automated update service (like `/usr/bin/certbot renew`) and wants to apply the option for preferred chain only to a particular domain, then the right place is in the config file at `/etc/letsencrypt/renewal/your.domain.name.conf` with this syntax:

```auto
... cut on purpose

[renewalparams]
account = ...obfuscated...
authenticator = webroot
preferred_chain = ISRG Root X1
webroot_path = /...obfuscated...,
server = https://acme-v02.api.letsencrypt.org/directory

... cut on purpose

```

And the renewal be forced with `/usr/bin/certbot renew --force-renewal`.

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [2 October 2021 09:59 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/17 "2021-10-02T09:59:47Z")

</div>

Yes as mentioned it was just a workaround and it is indeed not secure. Thanks for the reminder anyway - I've updated the top post with more info about it.

---

<div class="post-metadata">

**Author:** ![esc](https://avatars.discourse-cdn.com/v4/letter/e/a698b9/32.png) [@esc](https://discourse.joplinapp.org/u/esc)\
**Post date:** [3 October 2021 20:23 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/18 "2021-10-03T20:23:21Z")

</div>

unfortunately, adding a line did not help  
_preferred\_chain = ISRG Root X1_

letsencrypt certificate has been refreshed as you can see by date, but joplin desktop still won't sync with error.

Only Ignore TLS certificate errors helps ☹

---

<div class="post-metadata">

**Author:** ![CGamesPlay](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/cgamesplay/32/9236_2.png) [@CGamesPlay](https://discourse.joplinapp.org/u/CGamesPlay)\
**Post date:** [5 October 2021 17:17 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/19 "2021-10-05T17:17:18Z")

</div>

I've resolved the issue on my self-hosted Joplin cloud. The "preferred chain" solution does actually work, however simply telling certbot/traefik/whatever where to get new certificates doesn't cause it to replace old ones, so you actually need to delete your certificate store to have them get refreshed.

To verify that you're seeing the "correct" error, run a command like this one:

```auto
$ openssl s_client -connect joplin.example.com:443 -servername joplin.example.com
CONNECTED(00000005)
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
---
Certificate chain
 0 s:/CN=joplin.example.com
   i:/C=US/O=Let's Encrypt/CN=R3
 1 s:/C=US/O=Let's Encrypt/CN=R3
   i:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
 2 s:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
   i:/O=Digital Signature Trust Co./CN=DST Root CA X3
---
# Lines omitted...

    Start Time: 1633452339
    Timeout : 7200 (sec)
    Verify return code: 10 (certificate has expired)
---
^C

```

Note that you see "certificate has expired" as the error message, note that "ISRG Root X1" is listed as a signer **but so is "DST Root CA X3"**. The DST certificate is the expired one.

## Steps to resolve

1. Update your preferred chain to "ISRG Root X1".
2. Delete the currently-valid certificate.
3. Restart your services.

I use traefik, so the following config snippet suits step 1:

```toml
[certificatesResolvers.le.acme]
preferredChain = "ISRG Root X1"

```

To accomplish step 2 using my setup, I deleted the configured `acme.json` file (`certificatesResolvers.le.acme.storage` file).

To confirm that everything is working, rerun the same command from before and see the new output:

```auto
$ openssl s_client -connect joplin.example.com:443 -servername joplin.example.com
CONNECTED(00000005)
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = R3
verify return:1
depth=0 CN = joplin.example.com
verify return:1
---
Certificate chain
 0 s:/CN=joplin.example.com
   i:/C=US/O=Let's Encrypt/CN=R3
 1 s:/C=US/O=Let's Encrypt/CN=R3
   i:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
---
# Lines omitted...

    Start Time: 1633453694
    Timeout : 7200 (sec)
    Verify return code: 0 (ok)
^C

```

I ran these tests using LibreSSL 2.6.5.

---

<div class="post-metadata">

**Author:** ![luciandf](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/luciandf/32/2683_2.png) [@luciandf](https://discourse.joplinapp.org/u/luciandf)\
**Post date:** [6 October 2021 07:06 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/20 "2021-10-06T07:06:53Z")

</div>

sorry I am a bit late but I have alse experienced the certificate error. I self host with nextcloud.

It appears that this error only affects the windows client. Both the android and linux (manjaro in my case) clients work without the `Ignore TLS Certificate errors` in the settings.

---

<div class="post-metadata">

**Author:** ![arnoldoree](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/arnoldoree/32/9469_2.png) [@arnoldoree](https://discourse.joplinapp.org/u/arnoldoree)\
**Post date:** [6 October 2021 08:33 UTC](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638/21 "2021-10-06T08:33:35Z")

</div>

I'm afraid the Windows client only assertion isn't the case @luciandf. I have experienced the issue using the AppImage on Debian Linux Buster, with self-host Nextcloud secured with LetsEncrypt.

[Next page](https://discourse.joplinapp.org/t/fix-for-certificate-has-expired-error-with-joplin-cloud-and-self-hosted-sync-targets/20638.md?page=2)
