Skip to main content

Performance Issue: AppSMTP client connectivity issue

Last Updated:
2026-08-14 13:36:01
Event:
2026-08-14 10:13:00
Status:
Closed
Brief Description:
Resolved: Some AppSMTP clients have been unable to connect to AppSMTP. Affected AppSMTP clients will need to update their cert trust stores. See Full Description for instructions.
User Impact:
Some AppSMTP clients may be unable to connect to AppSMTP at this time. Affected AppSMTP clients will need to update their cert trust stores.
Workaround:
There is no workaround for this issue
Current Status:
This issue is resolved. Affected AppSMTP clients will need to update their cert trust stores. See Full Description for instructions. 
Services Affected:
Application-Generated Email
Subsites Affected:
AppSMTP
Full Description:
Some AppSMTP clients have been unable to connect to AppSMTP. Affected AppSMTP clients will need to update their cert trust stores as follows:

  1. Get "domain-validate" RSA keys, and if possible ECC keys from InCommon Intermediate CAs
  2. To fully support all options at Cornell also import Org-validated key chains
  • "domain-validate" is for servers getting certs directly from certinext
  • "org-validated" is for servers getting certs from Idmgmts ACME-Proxy 


CIT TDX ID:
2367000



Timeline of Changes

Description Current Status Date Time
Some AppSMTP clients have been unable to connect to AppSMTP. Affected AppSMTP clients will need to update their cert trust stores as follows:

  1. Get "domain-validate" RSA keys, and if possible ECC keys from InCommon Intermediate CAs
  2. To fully support all options at Cornell also import Org-validated key chains
  • "domain-validate" is for servers getting certs directly from certinext
  • "org-validated" is for servers getting certs from Idmgmts ACME-Proxy 


This issue is resolved. Affected AppSMTP clients will need to update their cert trust stores. See Full Description for instructions. 
2026-08-14 13:36:01
Some AppSMTP clients have been unable to connect to AppSMTP. Affected AppSMTP clients will need to update their cert trust stores as follows:

  1. Get "domain-validate" RSA keys, and if possible ECC keys from InCommon Intermediate CAs
  2. To fully support all options at Cornell also import Org-validated key chains
  • "domain-validate" is for servers getting certs directly from certinext
  • "org-validated" is for servers getting certs from Idmgmts ACME-Proxy 


Affected AppSMTP clients will need to update their cert trust stores. See Full Description for instructions. 
2026-08-14 11:40:43
Some AppSMTP clients have been unable to connect to AppSMTP.
IT staff are investigating the issue.
2026-08-14 10:27:30