Server Version#: 1.43.4.10903-e5521bd8c
Player Version#: 4.160.0
Platform: Debian 13 (LXC container), native install
My server’s certificate chains to Let’s Encrypt’s new Generation Y hierarchy:
0: CN=*.<redacted>.plex.direct — issuer: C=US, O=Let's Encrypt, CN=YR2
1: C=US, O=Let's Encrypt, CN=YR2 — issuer: C=US, O=ISRG, CN=Root YR
Watching the server log during a reachability cycle:
DEBUG - CERT: incomplete TLS handshake from 34.202.97.122: tlsv1 alert unknown ca (SSL routines)
DEBUG - [EventSourceClient/pubsub] MyPlex: reachability check - current mapping state: 'Mapped - Publishing'.
DEBUG - [EventSourceClient/pubsub] MyPlex: mapping state set to 'Mapped - Not Published (Not Reachable)'.
34.202.97.122 connecting in and immediately rejecting the handshake with unknown ca, followed seconds later by the reachability check failing, strongly indicates the prober itself doesn’t yet trust ISRG Root YR — the same root/intermediate trust-store lag that’s been affecting Linux distros generally (see the Let’s Encrypt community thread “Chain validation issues with YE/YR under Linux distributions”). My server’s chain is complete and valid; the external checker is the one failing to validate it.
Remote Access also periodically gets disabled outright, which looks like the client reacting to the failed reachability signal rather than a separate issue.