# TLS Certificate Transition

**URL:** <https://forums.plex.tv/t/tls-certificate-transition/689056>\
**Category:** Plex Media Server\
**Tags:** service-announcements\
**Created:** [February 10, 2021, 10:17pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056 "2021-02-10T22:17:24Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ridley](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ridley/32/297728_2.png) [@Ridley](https://forums.plex.tv/u/Ridley)\
**Post date:** [February 10, 2021, 10:17pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/1 "2021-02-10T22:17:25Z")

</div>

Starting today, we are beginning a transition to use a new certificate authority (CA) for TLS certificates for Plex Media Server. New certificates will be issued by [Let’s Encrypt](https://letsencrypt.org/). We’re beginning the rollout today with a small number of users running Plex Media Server (PMS) version 1.21.3.4021 and newer. By the end of the month, all new and renewed certificates will be from the new CA regardless of PMS version, though existing certs will continue to work until they approach expiration and are renewed. Users shouldn’t generally notice any significant changes, but we’re keeping an eye out for any possible compatibility issues; if you run into any problems related to the transition, please post in this thread describing them.

Along with the change of CA, we’re also making improvements to the way these new certificates are generated. This new mechanism produces smaller certificates with better performance, while also providing stronger security and privacy properties. Additionally, when these certificates are renewed, the new certificate will keep the same domain name as the previous one, which will avoid issues caused by stale client caches which you may have experienced during a certificate renewal in the past on older PMS versions. These generation improvements apply to PMS version 1.21.3.4021 and newer. We don’t anticipate any compatibility issues with this new mechanism, but again, if you encounter any problems, please post about them here.

[EDIT]  
The new CA is now available to all users. Thanks to everyone who tested things out before our wider rollout; we haven’t seen any major issues reported!

---

<div class="post-metadata">

**Author:** ![Ridley](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ridley/32/297728_2.png) [@Ridley](https://forums.plex.tv/u/Ridley)\
**Post date:** [February 10, 2021, 10:17pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/2 "2021-02-10T22:17:49Z")

</div>



---

<div class="post-metadata">

**Author:** ![kevin\_marchant](https://avatars.discourse-cdn.com/v4/letter/k/b782af/32.png) [@kevin\_marchant](https://forums.plex.tv/u/kevin_marchant)\
**Post date:** [February 10, 2021, 11:35pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/3 "2021-02-10T23:35:24Z")

</div>

Before I volunteer, I primarily play Plex content from the Community build for the RaspPi PlexMediaPlayer 2.55 and PlexMediaPlayer for Windows 2.58.

Whilst I can hope and imagine the Windows player might use the platform Windows keychain so might have the root cert for LetsEncrypt, I worry that the out-of-date LibreElec distro for the Pi might not.

Are these scenarios you’ve considered? How will the clients behave in the case of an invalid cert?

---

<div class="post-metadata">

**Author:** ![Ridley](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ridley/32/297728_2.png) [@Ridley](https://forums.plex.tv/u/Ridley)\
**Post date:** [February 11, 2021, 12:12am UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/4 "2021-02-11T00:12:21Z")

</div>

> [@kevin\_marchant](#):
>
> Whilst I can hope and imagine the Windows player might use the platform Windows keychain so might have the root cert for LetsEncrypt, I worry that the out-of-date LibreElec distro for the Pi might not.

I’ve double-checked and the certificate bundles we provide on both of those apps do contain the ISRG root. Even for devices that don’t have it (most notably older Android versions), we’re using a chain that includes a cross-sign from the DST root for the foreseeable future; see more details about this compatibility measure in [this Let’s Encrypt blog post](https://letsencrypt.org/2020/12/21/extending-android-compatibility.html). We may eventually remove the cross-signed root from our chain (and thus reduce its size further, improving connection performance for users) once usage of older devices has dropped and we’re confident that all of our supported platforms will work without it, but I wouldn’t worry about it for now.

---

<div class="post-metadata">

**Author:** ![pax0707](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/pax0707/32/326533_2.png) [@pax0707](https://forums.plex.tv/u/pax0707)\
**Post date:** [February 11, 2021, 12:42am UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/5 "2021-02-11T00:42:59Z")

</div>

Rebooted the server, the new cert is generated and loaded fine.  
Web and mobile apps working.

---

<div class="post-metadata">

**Author:** ![morton87](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/morton87/32/11188_2.png) [@morton87](https://forums.plex.tv/u/morton87)\
**Post date:** [February 11, 2021, 12:43am UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/6 "2021-02-11T00:43:29Z")

</div>

Will this have any ill effect if I am using the custom certificate settings and providing my own? I would guess not as you guys are updating the cert for unreadable name/domain you guys assigned back when you had digicert sign somethings, but just wanted to check and be sure.

---

<div class="post-metadata">

**Author:** ![Ridley](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ridley/32/297728_2.png) [@Ridley](https://forums.plex.tv/u/Ridley)\
**Post date:** [February 11, 2021, 12:50am UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/7 "2021-02-11T00:50:13Z")

</div>

> [@morton87](#):
>
> Will this have any ill effect if I am using the custom certificate settings and providing my own?

There should be no changes to custom certificate handling.

---

<div class="post-metadata">

**Author:** ![xInsertx](https://avatars.discourse-cdn.com/v4/letter/x/d78d45/32.png) [@xInsertx](https://forums.plex.tv/u/xInsertx)\
**Post date:** [February 11, 2021, 7:56am UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/8 "2021-02-11T07:56:10Z")

</div>

Is the rational for this change purely a cost cutting measure? I use LE a lot, nothing against it. Just seems like a lot of work for little benefit unless it’s cost related.

---

<div class="post-metadata">

**Author:** ![patrice.bertrand\_gmail.com](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@patrice.bertrand\_gmail.com](https://forums.plex.tv/u/patrice.bertrand_gmail.com)\
**Post date:** [February 11, 2021, 8:23am UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/9 "2021-02-11T08:23:19Z")

</div>

Is it fully compatible with the samsung TV client?

---

<div class="post-metadata">

**Author:** ![Ridley](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ridley/32/297728_2.png) [@Ridley](https://forums.plex.tv/u/Ridley)\
**Post date:** [February 11, 2021, 9:07am UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/10 "2021-02-11T09:07:04Z")

</div>

> [@patrice.bertrand\_gmail.com](#):
>
> Is it fully compatible with the samsung TV client?

Should be! We haven’t seen any issues with it in our internal testing, but please let us know if you run into anything on any particular device or firmware.

---

<div class="post-metadata">

**Author:** ![patrice.bertrand\_gmail.com](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@patrice.bertrand\_gmail.com](https://forums.plex.tv/u/patrice.bertrand_gmail.com)\
**Post date:** [February 11, 2021, 9:22am UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/11 "2021-02-11T09:22:11Z")

</div>

OK. You can switch me to test

---

<div class="post-metadata">

**Author:** ![\_jjorge](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/_jjorge/32/90859_2.png) [@\_jjorge](https://forums.plex.tv/u/_jjorge)\
**Post date:** [February 11, 2021, 12:44pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/12 "2021-02-11T12:44:08Z")

</div>

Switch me over @Ridley

---

<div class="post-metadata">

**Author:** ![mveinot](https://avatars.discourse-cdn.com/v4/letter/m/45deac/32.png) [@mveinot](https://forums.plex.tv/u/mveinot)\
**Post date:** [February 11, 2021, 1:02pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/13 "2021-02-11T13:02:57Z")

</div>

I have been manually generating LE certificates for my server for some time now, so having it automated would be great. How would I switch back to not-manual certificates?

---

<div class="post-metadata">

**Author:** ![rcork](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/rcork/32/4386_2.png) [@rcork](https://forums.plex.tv/u/rcork)\
**Post date:** [February 11, 2021, 3:58pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/14 "2021-02-11T15:58:37Z")

</div>

@Ridley i’ve rebooted my server but when i visit [https://app.plex.tv/desktop](https://app.plex.tv/desktop) the certificate still shows as being from DigiCert. However if i load the page directly from my server ([https://plex-server:32400](https://plex-server:32400)) then the certificate is from Let’s Encrypt. I do get a warning from Firefox because the certificate doesn’t match my server name (cert is for a plex.direct domain). Am i doing something wrong. Shouldn’t i get the new cert when launching via plex.tv?

---

<div class="post-metadata">

**Author:** ![nbdwt73](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@nbdwt73](https://forums.plex.tv/u/nbdwt73)\
**Post date:** [February 11, 2021, 4:31pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/15 "2021-02-11T16:31:21Z")

</div>

I too have the same issue - cert remains from DigiCert…

---

<div class="post-metadata">

**Author:** ![Ridley](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ridley/32/297728_2.png) [@Ridley](https://forums.plex.tv/u/Ridley)\
**Post date:** [February 11, 2021, 7:09pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/16 "2021-02-11T19:09:11Z")

</div>

> [@mveinot](#):
>
> How would I switch back to not-manual certificates?

Just remove your custom cert path in your server settings. Note that the automatic cert will still be generated and used even if you also have a custom cert.

> [@rcork](#):
>
> when i visit [https://app.plex.tv/desktop](https://app.plex.tv/desktop) the certificate still shows as being from DigiCert.

Are you looking at the cert for app.plex.tv itself, or for your server? Those are completely separate; this change does not affect the cloud service hosting app.plex.tv itself.

> [@nbdwt73](#):
>
> I too have the same issue - cert remains from DigiCert…

Same question.

---

<div class="post-metadata">

**Author:** ![tobyadmin](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/tobyadmin/32/87857_2.png) [@tobyadmin](https://forums.plex.tv/u/tobyadmin)\
**Post date:** [February 11, 2021, 7:11pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/17 "2021-02-11T19:11:13Z")

</div>

“This new mechanism produces smaller certificates with better performance, while also providing stronger security and privacy properties.”

Is it correct that you’re moving from RSA to ECDSA certificates?

I just want to say thank you to the crypto folks at Plex. Even with the RSA certs, I can see they are 4096 bit, which is “extra”. Also I can see the connection I’m making to my PMS is TLS 1.3 TLS\_AES\_256\_GCM\_SHA384 with X25519 curve, which are all excellent.

---

<div class="post-metadata">

**Author:** ![fly](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/fly/32/82069_2.png) [@fly](https://forums.plex.tv/u/fly)\
**Post date:** [February 11, 2021, 7:24pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/18 "2021-02-11T19:24:19Z")

</div>

While everything worked fine yesterday, today I can’t get Plex to play on any local or remote clients. It seems unlikely, but could this be related?

It looks like my last cert was pulled on 1/31 and the issuer is Plex Devices High Assurance CA3.

---

<div class="post-metadata">

**Author:** ![Ridley](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ridley/32/297728_2.png) [@Ridley](https://forums.plex.tv/u/Ridley)\
**Post date:** [February 11, 2021, 7:28pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/19 "2021-02-11T19:28:33Z")

</div>

> [@tobyadmin](#):
>
> Is it correct that you’re moving from RSA to ECDSA certificates?

Yup!

> [@fly](#):
>
> It looks like my last cert was pulled on 1/31 and the issuer is Plex Devices High Assurance CA3.

That’s an old cert, so your issue is unrelated to this change; please post in a separate thread.

---

<div class="post-metadata">

**Author:** ![nbdwt73](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@nbdwt73](https://forums.plex.tv/u/nbdwt73)\
**Post date:** [February 11, 2021, 7:44pm UTC](https://forums.plex.tv/t/tls-certificate-transition/689056/20 "2021-02-11T19:44:51Z")

</div>

Server side… Am getting an invalid cert message. It is from Let’s Encrypt though…

[Next page](https://forums.plex.tv/t/tls-certificate-transition/689056.md?page=2)
