Server Version#: 1.32
Player Version#:
I just updated it from 1.31 to 1.32.
I’m using a Let’s Encrypt certificate which worked correctly before the update.
The error is:
NET::ERR_CERT_COMMON_NAME_INVALID
Seems as if the “Custom certificate location” under network settings is being ignored.
Is it me, or anyone else has this issue?
1 Like
Update your cert creation,
There are many posts about this all over the forum.
OpenSSL v3.0.0 and PMS.
For those using their own domains and certificates with PMS ,
PMS 1.32.0.6865 and above updates OpenSSL from v1.1.1 to v3.0.0 .
(changed the numbering scheme in the process)
The consequence of this is OpenSSL v3 removed several “less secure” encryption methods.
The impact on you, if you’re using an older distributions where openssl v3 is not the default, if not already doing so, you will need pay special attention to how your certificates are generated
As example…
2 Likes
Hello
Sorry but I’ve the same issue. As you suggest I’ve renewed my certificate and I’ve updated my settings but my Plex Media Server is still using a *.plex.direct certificate and not mine.
I’ve never had this issue. Usually I update Plex Media Server without updating my certificate.
Thank you in advance for your help.
Sorry, I’ve found the answer:
Server Version#: 1.32.0.6918
Player Version#: N/A (web 4.100.1)
I have PMS configured with a SSL custom certificate. Having just upgraded to 1.32.0.6918, instead of the custom certificate, PMS serves a Let’s Encrypt certificate on CN: *..plex.direct. I can reproduce on two different servers.
The custom SSL certificate is configured in Settings → Network. The PMS configuration is unchanged before and after the upgrade.
% echo | openssl s_client -showcerts -servername <server name> -connect <s…
@romain789
Did you make the needed change to your certificate generation command line and restart PMS ? (as referenced directly above your post)
OpenSSL v3.0.0 and PMS.
For those using their own domains and certificates with PMS ,
PMS 1.32.0.6865 and above updates OpenSSL from v1.1.1 to v3.0.0 .
(changed the numbering scheme in the process)
The consequence of this is OpenSSL v3 removed several “less secure” encryption methods.
The impact on you, if you’re using an older distributions where openssl v3 is not the default, if not already doing so, you will need pay special attention to how your certificates are generated
As example…
pdan
April 13, 2023, 4:24pm
5
@romain789 This is the full solution, which worked for me: OpenSSL v3.0.0 and PMS.
Same problem. Never had any issues wth other updates.
Definetaly not my server certificate which is causing the problem
The server's security certificate comes from *.38b216a5b913463693e00993XXXXXX.plex.direct. This could be caused by a misconfiguration or an attacker intercepting your connection.
It reports strangely. (you asked for your cert, it only has its own. There’s a mismatch. That mismatch is what’s being reported.)
If you’re using 1.32.0 then UPDATE how you generate your certificate to AES-256 or better as shown in the Tips How-To
I have downgraded to 1.31.2.6810 and it is working again.
As of September 11, 2023, you won’t be able to use your existing encryption so you’ll have to update.
Please observe the expiration of the existing version v1.1.1 support
Either upgrade your cert creation now or later – your choice.
1 Like
system
Closed
July 12, 2023, 8:11pm
10
This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.