Stuck plex.direct certificate, Remote Access "Not Reachable"

PMS 1.43.4.10903 (linuxserver/plex, Docker host network, Unraid).
Machine identifier: ff2329374c2562c5e01401ba6de7b816e046e510
Cert CN: *.43dd6f289c4e4b31aed49337f5dee64c.plex.direct, issued Sep 12 2026, chain is YR1 → ISRG Root YR with no X1 cross-sign.

Port 32400 is confirmed open from the internet (canyouseeme and a cellular phone both reach /identity over http and https).

The reachability prober fails every time:
CERT: incomplete TLS handshake from [::ffff:34.239.73.157]: tlsv1 alert unknown ca
MyPlex: mapping state set to ‘Mapped - Not Published (Not Reachable)’
Removing CertificateUUID and restarting re-fetched the same certificate.

Could staff please revoke/re-issue this server’s plex.direct certificate so it comes back on the cross-signed chain?

Can I get an update from Plex staff for this?

Any ideas I can try.

Still no remote access 3 days later.

You can try to force the cert to refresh. Stop plex, go to the Cache directory in the Plex Media Server folder, remove (don’t delete) the *.p12 file, and start plex back up. It should download a new cert.

It seems to have come right on its own now.