  1. Hi, You are right, appending the CA certificate PEM to the fullchain.pem file before converting it into .pfx using the above command worked. I used the PEM at https://censys.io/certificates/0687260331a72403d909f105e69bcf0d32e1bd2493ffc6d9206d11bcd6770739/pem
  2. Hi, I am using ESET ERA on a VPS with Ubuntu 16.04 x64. and I used Letsencrypt certificate for https. While on version 6 of ESET, i used the following command to generate the required .pfx file for MDC: sudo openssl pkcs12 -inkey /etc/letsencrypt/live/my.domain/privkey.pem -in /etc/letsencrypt/live/my.domain/fullchain.pem -export -out /etc/letsencrypt/live/my.domain/certificate.pfx -password pass:pass123 However, now that I am on version 7, ESET gives an alert that 'HTTPS certificate chain is incomplete. Enrollment is not allowed' Can anyone please give a step by step guide on how to include the root CA certificate of Letsencrypt in the .pfx file so that it is accepted by ESET 7. Thanks