On Mon, Oct 04, 2021 at 05:10:41PM +0200, Julien Cristau wrote: > I think what you're seeing can be explained if you had > ca-certificates/trust_new_crts disabled (see debconf-show > ca-certificates) when ISRG Root X1 was added, in which case the "new" > root wouldn't be in your bundle and so you wouldn't have a trust path to > LE certs after the DST Root's expiration.
Yep, it was on 'ask' but I do unattended upgrades. Thanks -- Aristeu