The AddTrust External CA Root certificate expired on May 30, 2020, causing alerts for servers that include it unnecessarily in their certificate chain. The post explains how to verify the issue using openssl commands, why the expiring root certificate is technically not needed for modern clients, and how to fix it by removing or replacing the certificate from your web server's intermediate certificate chain (Nginx or Apache). It also explains why Oh Dear monitors all certificates sent by a server and announces upcoming configurable alerting behavior for root certificate validation.

7m read timeFrom ohdear.app
Post cover image
Table of contents
What are the AddTrust External CA Root expiration notifications? #Verify that the SSL certificates are indeed about to expire #Validating the SSL Certificate Path #Replace or remove the old root-certificate in your chain #Why does Oh Dear report on these certificates? #Update: we will modify our alerting settings #
152 Impressions