# Letsencrypt root CA certificate expiration

**URL:** <https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635>\
**Category:** Support\
**Created:** [30 September 2021 15:51 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635 "2021-09-30T15:51:29Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![phirestalker](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/phirestalker/32/9855_2.png) [@phirestalker](https://discourse.joplinapp.org/u/phirestalker)\
**Post date:** [30 September 2021 15:51 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/1 "2021-09-30T15:51:30Z")

</div>

The root CA certificate for Letsencrypt expires today. They have changed to a new provider, but some older systems or libraries do not support it. I am able to browse to my Joplin server that is signed with a Letsencrypt cert, but Joplin reports certificate expired.

For reference: [https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/](https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/)

For other support queries please indicate:

- Joplin 2.4.9 (prod, darwin)
- MacOS 11.6
- syncing with Joplin server docker image through Traefik revers proxy

---

<div class="post-metadata">

**Author:** ![Yajo](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/yajo/32/8496_2.png) [@Yajo](https://discourse.joplinapp.org/u/Yajo)\
**Post date:** [30 September 2021 15:55 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/2 "2021-09-30T15:55:48Z")

</div>

Same here! I'm using the flatpak version. Joplin 2.4.9.

---

<div class="post-metadata">

**Author:** ![phirestalker](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/phirestalker/32/9855_2.png) [@phirestalker](https://discourse.joplinapp.org/u/phirestalker)\
**Post date:** [30 September 2021 16:06 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/3 "2021-09-30T16:06:56Z")

</div>

Luckily, we can temporarily "ignore TLS errors" in the advanced settings under the synchronization section.

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 16:07 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/4 "2021-09-30T16:07:11Z")

</div>

Anyone knows how to fix this?

Edit: I'm watching this thread and will try to provide a solution as soon as one is available: [[Bug]: Let's Encrypt root CA isn't working properly · Issue #31212 · electron/electron · GitHub](https://github.com/electron/electron/issues/31212)

---

<div class="post-metadata">

**Author:** ![OddBall](https://avatars.discourse-cdn.com/v4/letter/o/34f0e0/32.png) [@OddBall](https://discourse.joplinapp.org/u/OddBall)\
**Post date:** [30 September 2021 17:45 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/5 "2021-09-30T17:45:08Z")

</div>

This was driving me absolutely nuts until I found out that many people are running into this same issue. If I understand right something in Joplin needs to be changed to correct this? Or does my admin need to fix something on the server side?

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 17:52 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/6 "2021-09-30T17:52:27Z")

</div>

Something will need to be fixed on the app but it's unclear what at this point. In the meantime you should be able to fix the server using this method: [[Bug]: Let's Encrypt root CA isn't working properly · Issue #31212 · electron/electron · GitHub](https://github.com/electron/electron/issues/31212#issuecomment-931486784)

---

<div class="post-metadata">

**Author:** ![OddBall](https://avatars.discourse-cdn.com/v4/letter/o/34f0e0/32.png) [@OddBall](https://discourse.joplinapp.org/u/OddBall)\
**Post date:** [30 September 2021 17:59 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/7 "2021-09-30T17:59:26Z")

</div>

looks like they have a proposed fix

> <https://github.com/jviotti/electron/commit/d81a71a638faea759eb41431aa65775cb87a8ed2>
>
> Fixes: https://github.com/electron/electron/issues/31212
> Signed-off-by: Juan Cru…z Viotti \<jv@jviotti.com\>

---

<div class="post-metadata">

**Author:** ![james-carroll](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/james-carroll/32/28844_2.png) [@james-carroll](https://discourse.joplinapp.org/u/james-carroll)\
**Post date:** [30 September 2021 18:07 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/8 "2021-09-30T18:07:07Z")

</div>

I think there's an unfortunate chance that this might only end up applied to the actively supported Electron versions, (13, 14, 15). Since this problem effectively breaks every Electron version prior, I doubt they'd rebuild earlier releases because there has to be a line drawn somewhere (there's people saying this effects Electron 8 that they're still actively using for example).

---

<div class="post-metadata">

**Author:** ![OddBall](https://avatars.discourse-cdn.com/v4/letter/o/34f0e0/32.png) [@OddBall](https://discourse.joplinapp.org/u/OddBall)\
**Post date:** [30 September 2021 18:09 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/9 "2021-09-30T18:09:14Z")

</div>

looks like it's only a few lines of code for the fix if that is the verified fix couldn't someone just backport it into the older version of electron?

---

<div class="post-metadata">

**Author:** ![james-carroll](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/james-carroll/32/28844_2.png) [@james-carroll](https://discourse.joplinapp.org/u/james-carroll)\
**Post date:** [30 September 2021 18:20 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/10 "2021-09-30T18:20:16Z")

</div>

The backporting might be fairly trivial, but the build process for Electron takes hours to days even on dedicated machinery, combined with multiple versions and multiple architectures, I doubt Microsoft would bother with anything that isn't officially supported still.

npm doesn't build Electron, it downloads pre-compiled binaries. Building it just takes forever.

For example, setting up Chromium on ARM64 takes Ubuntu/Canonical 3 days.

---

<div class="post-metadata">

**Author:** ![OddBall](https://avatars.discourse-cdn.com/v4/letter/o/34f0e0/32.png) [@OddBall](https://discourse.joplinapp.org/u/OddBall)\
**Post date:** [30 September 2021 18:24 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/11 "2021-09-30T18:24:33Z")

</div>

okay so it sounds like fix it on the backend because the app may be fixed basically never.

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 19:04 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/12 "2021-09-30T19:04:38Z")

</div>

I'm really hoping they'll consider backporting the fix because it's a major problem for thousands of apps out there, and many of these can't easily upgrade Electron.

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 19:08 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/13 "2021-09-30T19:08:44Z")

</div>

Ok looks like they'll only backport to v12 and we're on v10. There's a version that's no good for us due to sandbox changes but I forgot which one (maybe v13? 🤞) . Hopefully we can at least upgrade to v12 without too much trouble.

[fix: Enable X509\_V\_FLAG\_TRUSTED\_FIRST flag in BoringSSL by jviotti · Pull Request #31213 · electron/electron · GitHub](https://github.com/electron/electron/pull/31213#issuecomment-931587075)

---

<div class="post-metadata">

**Author:** ![OddBall](https://avatars.discourse-cdn.com/v4/letter/o/34f0e0/32.png) [@OddBall](https://discourse.joplinapp.org/u/OddBall)\
**Post date:** [30 September 2021 19:32 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/14 "2021-09-30T19:32:24Z")

</div>

I assume whatever is implemented is going to take quite some time?

---

<div class="post-metadata">

**Author:** ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)\
**Post date:** [30 September 2021 20:09 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/15 "2021-09-30T20:09:28Z")

</div>

No ETA but it bothers me enough that I'll probably look at it quite soon.

---

<div class="post-metadata">

**Author:** ![kartoo](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/kartoo/32/324_2.png) [@kartoo](https://discourse.joplinapp.org/u/kartoo)\
**Post date:** [30 September 2021 23:35 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/16 "2021-09-30T23:35:14Z")

</div>

I have the same issue with Joplin on my Windows. I was able to fix the Chrome having issues with LE sites by installing their root cert into the Windows cert store but Joplin (also guessing all other Electron apps) do not accept that solution.

---

<div class="post-metadata">

**Author:** ![tessus](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/tessus/32/13_2.png) [@tessus](https://discourse.joplinapp.org/u/tessus)\
**Post date:** [1 October 2021 00:36 UTC](https://discourse.joplinapp.org/t/letsencrypt-root-ca-certificate-expiration/20635/17 "2021-10-01T00:36:45Z")

</div>

use this one instead:

> [@Fix for "Certificate has expired" error with Joplin Cloud and self-hosted sync targets](https://discourse.joplinapp.org/t/certificate-has-expired-error-with-joplin-cloud-and-workaround/20638):
>
> Updates: The issue has been resolved in Joplin Cloud, so if you had the "Ignore TLS certificate errors" option enabled, don't forget to switch it off as it is not secure. If you are self hosting and are having troubles with this bug, please give a try to the latest pre-release, which includes a permanent fix: [Pre-release v2.5 is now available (Updated 2 Oct)](https://discourse.joplinapp.org/t/pre-release-v2-5-is-now-available-updated-2-oct/20702) Some of you might be experiencing an error "Certificate has expired" when synchronising with Joplin Cloud (and possibly other ser…
