# Nextcloud App untrusted certificate, OK in browser

**URL:** <https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532>\
**Category:** ℹ️ Support\
**Tags:** letsencrypt\
**Created:** [September 30, 2021, 5:46am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532 "2021-09-30T05:46:26Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![kosta88](https://help.nextcloud.com/letter_avatar/kosta88/32/5_5575768a8748004e209b776fc1b2916d.png) [@kosta88](https://help.nextcloud.com/u/kosta88)\
**Post date:** [September 30, 2021, 5:46am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/1 "2021-09-30T05:46:26Z")

</div>

Hello,

I have an issue where my LE certificate on the firewall updated, browser is showing the correct certificate, but the app under windows does not, and gives me untrusted certificate error.  
Nextcloud is running on the Ubuntu server.  
App is on windows.  
Both are the latest version: 22.1.1 and 3.3.4.  
I tried reinstall/repair of the app, that didn’t help, also tried logging out of the account and logging back in, same error.  
Can someone help please?  
Thank you

---

<div class="post-metadata">

**Author:** ![W4Steli](https://help.nextcloud.com/letter_avatar/w4steli/32/5_5575768a8748004e209b776fc1b2916d.png) [@W4Steli](https://help.nextcloud.com/u/W4Steli)\
**Post date:** [September 30, 2021, 6:50am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/2 "2021-09-30T06:50:35Z")

</div>

Hi,

i can confirm the same thing since today, on two different sites … Web is ok, Android App is ok, but the Win Client fails the connection due to a Certificate Validation error.

But the error is popping for an **LetsEncypt intermediate CA certficate** which expired yesterday evening. Is the Win Client using its own Root CA list to trust and not the systems one?  
 ![2021-09-30_08-36-43](https://help.nextcloud.com/uploads/default/original/3X/9/0/90c20fb1de60807ead9e05dc83c6cf8ba2a6dd83.png)

Had a quick look in the install folder of the Client but found nothing.

---

<div class="post-metadata">

**Author:** ![Taomyn](https://help.nextcloud.com/user_avatar/help.nextcloud.com/taomyn/32/18589_2.png) [@Taomyn](https://help.nextcloud.com/u/Taomyn)\
**Post date:** [September 30, 2021, 7:04am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/3 "2021-09-30T07:04:35Z")

</div>

I have the exact same issue on multiple systems, at first it was both internal and external accesses but I fixed the internal by updating the intermediate certificate for R3, but this hasn’t helped for external access so far but that could be because it’s using the firewall’s own copy of the certificates as it’s going through HAProxy whereas internal it’s direct to the Nextcloud server.

---

<div class="post-metadata">

**Author:** ![devnull](https://help.nextcloud.com/user_avatar/help.nextcloud.com/devnull/32/27793_2.png) [@devnull](https://help.nextcloud.com/u/devnull)\
**Post date:** [September 30, 2021, 7:09am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/4 "2021-09-30T07:09:37Z")

</div>

I found this for you:  
[DST Root CA X3 Expiration (September 2021) - Let's Encrypt](https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/)  
[Let's Encrypt's Root Certificate is expiring!](https://scotthelme.co.uk/lets-encrypt-old-root-expiration/)

But sorry i have got no solution for your problem.

Found also this: [Let's Encrypt DST Root CA X3 expiry Sept 30th 2021 | Certify The Web Docs](https://docs.certifytheweb.com/docs/kb/kb-202109-letsencrypt/)

> Windows PC
> 
> On windows PCs, simply browsing to a website using Chrome, Edge etc with updated the client trust store with the required certificates. Browsing to [https://valid-isrgrootx1.letsencrypt.org/](https://valid-isrgrootx1.letsencrypt.org/) will prompt Windows to include _ISRG Root X1_ in its trust store automatically.

Sorry does not work for me. No message to include something.

---

<div class="post-metadata">

**Author:** ![tflidd](https://help.nextcloud.com/letter_avatar/tflidd/32/5_5575768a8748004e209b776fc1b2916d.png) [@tflidd](https://help.nextcloud.com/u/tflidd)\
**Post date:** [September 30, 2021, 8:26am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/5 "2021-09-30T08:26:34Z")

</div>

> [@Taomyn](#):
>
> the firewall’s own copy of the certificates as it’s going through HAProxy whereas internal it’s direct to the Nextcloud server.

So check with the firewall, how to update certificates there. Does it just cache the certificates? Perhaps they have tutorials like they did for pfsense:  
[https://blog.tastatursport.de/2021/09/pfsense-2-5-x-letsencrypt-haproxy-proper-mitigation-of-expiring-le-intermediate-ca/](https://blog.tastatursport.de/2021/09/pfsense-2-5-x-letsencrypt-haproxy-proper-mitigation-of-expiring-le-intermediate-ca/)

---

<div class="post-metadata">

**Author:** ![Taomyn](https://help.nextcloud.com/user_avatar/help.nextcloud.com/taomyn/32/18589_2.png) [@Taomyn](https://help.nextcloud.com/u/Taomyn)\
**Post date:** [September 30, 2021, 10:40am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/6 "2021-09-30T10:40:22Z")

</div>

So I have resolved the issue, but it was made more confusing because all the browsers I tested access with whether internal and external, on PC or mobile, all showed the newer server certificate, but what the NC Windows client was actually showing was the LE intermediate CA certificate - it’s obviously not just me that didn’t spot that at first.

Also the firewall running my HAProxy and also managing the LE certificates was still using the older intermediate CA certificate when renewing my certificates even though I had a while back installed the new one that has now taken over. After deleting the expired one and then forcefully renewing all 20+ certificates which had to be done one at a time, the Windows NC client was happy again.

I hope that makes sense and that it helps anyone else with similar problems, so for me all is back to normal.

---

<div class="post-metadata">

**Author:** ![tflidd](https://help.nextcloud.com/letter_avatar/tflidd/32/5_5575768a8748004e209b776fc1b2916d.png) [@tflidd](https://help.nextcloud.com/u/tflidd)\
**Post date:** [October 1, 2021, 6:53am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/7 "2021-10-01T06:53:42Z")

</div>

7 posts were split to a new topic: [Letsencrypt ISRG Root X1 local lookup not found](https://help.nextcloud.com/t/letsencrypt-isrg-root-x1-local-lookup-not-found/124608)

---

<div class="post-metadata">

**Author:** ![bnmihai](https://help.nextcloud.com/letter_avatar/bnmihai/32/5_5575768a8748004e209b776fc1b2916d.png) [@bnmihai](https://help.nextcloud.com/u/bnmihai)\
**Post date:** [October 1, 2021, 11:16am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/8 "2021-10-01T11:16:16Z")

</div>

I have the same issue. I solve the problem like this: close app nexcloud on your PC and from default browser (edge/chrome/firefox/etc) enter on this site [https://valid-isrgrootx1.letsencrypt.org/](https://valid-isrgrootx1.letsencrypt.org/) . It works.

---

<div class="post-metadata">

**Author:** ![BeforeCloud](https://help.nextcloud.com/user_avatar/help.nextcloud.com/beforecloud/32/27563_2.png) [@BeforeCloud](https://help.nextcloud.com/u/BeforeCloud)\
**Post date:** [October 1, 2021, 12:20pm UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/9 "2021-10-01T12:20:13Z")

</div>

This is a bug in the NextCloud Windows client: [ISRG Root X1 Certificate not trusted · Issue #3858 · nextcloud/desktop · GitHub](https://github.com/nextcloud/desktop/issues/3858)

They are working on a fix right now.

---

<div class="post-metadata">

**Author:** ![Alternativend](https://help.nextcloud.com/user_avatar/help.nextcloud.com/alternativend/32/32738_2.png) [@Alternativend](https://help.nextcloud.com/u/Alternativend)\
**Post date:** [October 26, 2021, 1:23pm UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/10 "2021-10-26T13:23:34Z")

</div>

Is there any progress on this?

---

<div class="post-metadata">

**Author:** ![devnull](https://help.nextcloud.com/user_avatar/help.nextcloud.com/devnull/32/27793_2.png) [@devnull](https://help.nextcloud.com/u/devnull)\
**Post date:** [October 26, 2021, 1:25pm UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/11 "2021-10-26T13:25:18Z")

</div>

Read [this](https://help.nextcloud.com/t/certificate-has-expired-for-apps-nextcloud-and-nextcloud-com/124569/2)

---

<div class="post-metadata">

**Author:** ![rmoran](https://help.nextcloud.com/letter_avatar/rmoran/32/5_5575768a8748004e209b776fc1b2916d.png) [@rmoran](https://help.nextcloud.com/u/rmoran)\
**Post date:** [November 12, 2021, 3:51pm UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/12 "2021-11-12T15:51:45Z")

</div>

Hello, I’m having the same issue. I moved my reverse proxy on unraid from SWAG (which had no certificate problem) to Nginx Proxy Manager. I am using Lets Encrypt for my domain [nextcloud.server.com](http://nextcloud.server.com) and it works great on all browsers, but not the desktop apps. I get the same error you mentioned. I have never messed with certificates. I do not know where to find them to delete the old one. I’m using unraid 6.9.2 for my nextcloud. Any advice or directions would be appreciated. Thanks

---

<div class="post-metadata">

**Author:** ![manuth](https://help.nextcloud.com/letter_avatar/manuth/32/5_5575768a8748004e209b776fc1b2916d.png) [@manuth](https://help.nextcloud.com/u/manuth)\
**Post date:** [June 30, 2023, 11:55am UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/13 "2023-06-30T11:55:16Z")

</div>

This did the trick, thank you so much!  
Could you please explain as to why this is working?

This doesn’t make any sense to me.

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 14, 2024, 3:19pm UTC](https://help.nextcloud.com/t/nextcloud-app-untrusted-certificate-ok-in-browser/124532/14 "2024-12-14T15:19:49Z")

</div>


