# Let's Encrypt-provided ECC certificate rejected/ignored

**URL:** https://forums.plex.tv/t/lets-encrypt-provided-ecc-certificate-rejected-ignored/927250
**Category:** Plex Media Server
**Tags:** server-synology
**Created:** [July 27, 2025, 5:39pm UTC](https://forums.plex.tv/t/lets-encrypt-provided-ecc-certificate-rejected-ignored/927250 "2025-07-27T17:39:38Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![paulschreiber](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@paulschreiber](https://forums.plex.tv/u/paulschreiber)
#### Post date: [July 27, 2025, 5:39pm UTC](https://forums.plex.tv/t/lets-encrypt-provided-ecc-certificate-rejected-ignored/927250/1 "2025-07-27T17:39:38Z")

</div>

Server Version#: 1.41.5.9626-72009626  
Hardware: Synology DS1525+ running DSM 7.2.2-72806.  
acme.sh: 3.1.2

I installed acme.sh and obtained a certificate for my NAS:

```auto
./acme.sh --server letsencrypt --issue -d mydomain --dns dns_cf --home /usr/local/share/acme.sh
./acme.sh -d mydomain --deploy --deploy-hook synology_dsm --home /usr/local/share/acme.sh

```

I attempted to convert the certificate to PKCS12 for use with Plex:

```auto
./acme.sh --toPkcs -d mydomain --home /usr/local/share/acme.sh

```

In Plex \> Settings \> Network \> Custom certificate location, I specified the path to the pfx file ACME generate and restarted Plex. Plex ignored this certificate and served the default one using xxx.plex.direct.

[Previous discussion from 2023](https://forums.plex.tv/t/plex-not-using-my-ssl-certificate-after-v1-31-3-6868-tried-1-32-1-6918-1-32-1-6999-on-server22/840638) noted an OpenSSL 3.0 upgrade as deprecating support for older, insecure encryption method.

I would expect that a new installation of ACME would use modern, secure encryption methods and that its pkcs conversion would also be suitable.

1. Why is Plex rejecting the ECC cert?
2. Can I pass some parameters to `acme.sh --toPkcs` to convert to AES-256-CBC?
3. Alternatively, should I pass parameters to `./acme.sh --server letsencrypt --issue …` to generate the cert with a different algorithm?

---

<div class="post-metadata">

### Author: ![tom80H](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/tom80h/32/19753_2.png) [@tom80H](https://forums.plex.tv/u/tom80H)
#### Post date: [July 27, 2025, 6:15pm UTC](https://forums.plex.tv/t/lets-encrypt-provided-ecc-certificate-rejected-ignored/927250/2 "2025-07-27T18:15:06Z")

</div>

Maybe this helps

> [@Custom certificate not loaded](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/4):
>
> You create the P12 externally to PMS first. My cert is from Let’s Encrypt, managed by Pfsense and the ACME management software in PfSense openssl pkcs12 -export -out my-domain.p12 -inkey my-domain-production.key -in my-domain-production.crt \ -certfile Acme-LE.crt \ -password pass:password I put the p12 where PMS can read it

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)
#### Post date: [October 25, 2025, 6:15pm UTC](https://forums.plex.tv/t/lets-encrypt-provided-ecc-certificate-rejected-ignored/927250/3 "2025-10-25T18:15:59Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
