Hi,

Is your SLES 12 up to date?

The SLES12SP4 - Pool and Updates repositories are  being used and zypper refresh && zypper update tells me it is up to date.
This is a freshly installed machine.


The DST Root CA X3 was removed from our CA Bundle to avoid triggering
this problem.

Ciao, Marcus
On Tue, Dec 07, 2021 at 01:07:09PM +0000, Mathias Radtke wrote:
> Hi we are currently struggling with testing our sles12 packages on download.opensuse.org
>
> The certificate gets rejected because it is expired
>
>
> openssl s_client -showcerts -connect download.opensuse.org:443
>
> CONNECTED(00000003)
>
> depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3
>
> verify error:num=10:certificate has expired
>
> notAfter=Sep 30 14:01:15 2021 GMT
>
> ---
>
> Certificate chain
>
>  0 s:/CN=opensuse.org
>
>    i:/C=US/O=Let's Encrypt/CN=R3
>