"/var/etc/acme-client/home/"
echo -n | openssl s_client -connect server:443
CONNECTED(00000005)depth=0 CN = server.meine-domain.deverify error:num=20:unable to get local issuer certificateverify return:1depth=0 CN = server.meine-domain.deverify error:num=21:unable to verify the first certificateverify return:1---Certificate chain 0 s:CN = server.meine-domain.de i:C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3---
Verify return code: 21 (unable to verify the first certificate)
---Certificate chain 0 s:CN = firewall.meine-domain.de i:C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3 1 s:C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3 i:O = Digital Signature Trust Co., CN = DST Root CA X3---
DST_Root_CA_X3.pem -> /usr/share/ca-certificates/mozilla/DST_Root_CA_X3.crt
Am besten mal das cer anschauen in text editor.
-rwxr-x--- 1 root wheel 1648 Jan 29 10:08 ca.cer*-rwxr-x--- 1 root wheel 3933 Jan 29 10:08 fullchain.cer*-rwxr-x--- 1 root wheel 2285 Jan 29 10:08 server.meine-domain.de.cer*-rwxr-x--- 1 root wheel 958 Jan 29 10:08 server.meine-domain.de.conf*-rwxr-x--- 1 root wheel 1700 Jan 29 10:08 server.meine-domain.de.csr*-rwxr-x--- 1 root wheel 220 Jan 29 10:08 server.meine-domain.de.conf*-rwxr-x--- 1 root wheel 3243 Nov 21 11:32 server.meine-domain.de.key*
Verify return code: 0 (ok)
/var/etc/acme-client/home/server.meine-domain.de