For anyone finding this topic later because of the YR1 / YE2 issuer errors in the logs:
I reproduced that specific certificate-verification failure while investigating a separate Let’s Encrypt issue. cert_exists() currently keeps only the first certificate from ca.cer, which can discard a certificate required to build the chain.
Using:
openssl verify -untrusted ca.cer fullchain.cer
fixes the verification in the cases I tested. I verified actual RSA and ECDSA chains and completed a rebuild that reused both existing certificates without triggering forced reissuance.
I documented the issue and proposed a fix here:
PR: FIX: preserve the Let’s Encrypt issuer chain in cert_exists - Pull Request #1136
This only concerns the certificate issuer-verification errors shown above; it is not intended to explain the separate application issue that was ultimately resolved in this topic.