I recently ran into a related issue in cert_exists() while investigating Let’s Encrypt certificate reuse.
In my case the certificate files and both RSA/ECDSA directories were present, but the current check was still returning false because openssl x509 -in ca.cer only keeps the first certificate from the issuer bundle.
Using:
openssl verify -untrusted ca.cer fullchain.cer
fixed the verification. I also tested it with actual RSA and ECDSA certificates and completed a rebuild that reused both existing certificates without triggering forced reissuance.
This may not be the same root cause as the missing _ecc directory described in this topic, but it affects the same cert_exists() path, so I’m linking it here in case it’s useful for anyone hitting similar symptoms.
Report: Let's Encrypt cert_exists() truncates the CA chain, causing forced reissuance and rate-limit failures
PR: FIX: preserve the Let's Encrypt issuer chain in cert_exists - Pull Request #1136 - discourse/discourse_docker - GitHub