Apple devices reporting expiry issues with Let’s Encrypt SSL certificates in MDaemon after 29th September 2021
Let’s Encrypt is a free root trusted SSL provider and MDaemon integrates with it to offer free 90-day root trusted SSL certificates which are automatically renewed.
On the 29th September at 20:21 a built-in DST Root CA (Certificate Authority) expired, which may have caused issues with Apple devices connecting to MDaemon via ActiveSync, IMAP or Webmail, despite the fact that the Let’s Encrypt SSL certificate in MDaemon had not expired.
Typically, the device would prompt like this as it is caching that old DST Root CA:
The easiest “fix” to this issue is to take the following steps in MDaemon and issue a brand new Let’s Encrypt SSL certificate that the Apple device then needs to re-validate:
- At Setup -> Security Manager -> SSL & TLS -> MDaemon select the active Let’s Encrypt SSL Certificate and choose Delete (do not press APPLY or OK).
- Move to the Let’s Encrypt tab under Setup -> Security Manager -> SSL & TLS and choose Run Now. Within 1-2 minutes MDaemon will restart and a new Let’s Encrypt SSL certificate will have been created and bound to its SSL ports.
- Test the Apple device to confirm the warning regarding the old expired DST Root Certificate Authority has now disappeared.
Related Articles
Configuring ActiveSync in MDaemon and addressing common configuration issues
MDaemon’s ActiveSync options are located at Setup -> Mobile Device Management -> ActiveSync and it’s necessary to enable ActiveSync in this location: Once enabled MDaemon will generate an ActiveSync 30 day trial key automatically. The ActiveSync ...
Using a Let's Encrypt certificate with MDaemon
Let's Encrypt is a a free, automated, and open certificate authority brought to you by the non-profit Internet Security Research Group (ISRG) which allows you to create a free root trusted SSL certificate for your domain(s). Thankfully, the MDaemon ...
Configuring SSL for SMTP, IMAP and POP3 in MDaemon
This article details how you’d configure MDaemon so that it accepts SMTP, IMAP and POP3 connections over SSL. Choose Security -> Security Manager-> SSL & TLS -> MDaemon. Click Enable SSL, STARTTLS, and STLS. Click Enable the dedicated SSL ports for ...
Creating a Certificate Signing Request and Importing a Third-Party SSL Certificate for MDaemon
MDaemon does not include a method for creating a Certificate Signing Request (CSR) in order to obtain a third-party SSL certificate issued by a Trusted Root Authority (such as Comodo or GoDaddy), as Windows has its own command-line utility, ...
How do I move or copy an SSL certificate from one PC to another?
If you need to move a root trusted or self-signed SSL certificate from one Windows Machine to another this article will detail the process. In this example, we are moving a root trusted SSL certificate we purchased for www.zensoftware.co.uk to a new ...