Remote Access stuck "Not Reachable"

Server Version#: 1.43.4.10903-e5521bd8c
Player Version#: 4.160.0
Platform: Debian 13 (LXC container), native install

My server’s certificate chains to Let’s Encrypt’s new Generation Y hierarchy:

0: CN=*.<redacted>.plex.direct — issuer: C=US, O=Let's Encrypt, CN=YR2
1: C=US, O=Let's Encrypt, CN=YR2 — issuer: C=US, O=ISRG, CN=Root YR

Watching the server log during a reachability cycle:

DEBUG - CERT: incomplete TLS handshake from 34.202.97.122: tlsv1 alert unknown ca (SSL routines)
DEBUG - [EventSourceClient/pubsub] MyPlex: reachability check - current mapping state: 'Mapped - Publishing'.
DEBUG - [EventSourceClient/pubsub] MyPlex: mapping state set to 'Mapped - Not Published (Not Reachable)'.

34.202.97.122 connecting in and immediately rejecting the handshake with unknown ca, followed seconds later by the reachability check failing, strongly indicates the prober itself doesn’t yet trust ISRG Root YR — the same root/intermediate trust-store lag that’s been affecting Linux distros generally (see the Let’s Encrypt community thread “Chain validation issues with YE/YR under Linux distributions”). My server’s chain is complete and valid; the external checker is the one failing to validate it.

Remote Access also periodically gets disabled outright, which looks like the client reacting to the failed reachability signal rather than a separate issue.

Fix that worked: Settings → Network → enable Strict TLS configuration, then stop Plex, move Cache/certificate.p12 aside, and restart — forces a new cert. Confirmed via openssl s_client -showcerts that it re-issued as ECDSA, chaining YE2 → Root YE → X2 → X1 (fully cross-signed to the old trusted root) instead of the dead-end RSA YR2 → Root YR chain. Credit to @BeerMan81’s post above for the fix.

saw from here Stuck plex.direct certificate — tlsv1 alert unknown ca — please reset (Docker/WSL) - #8 by BeerMan81

Helped me too!