LE's R3 certificate expiring today sure has contributed to my headache.


to clarify: the intermediary CA was replaced, but because i'm an idiot and trusted haproxy/opnsense to vibe, haproxy is still supplying the outdated intermediary CA, breaking the chain

