At the end I contacted Gandi support and they confirmed the hash values of the certificates so I could accept them manually. I suspect it’s a configuration error on their side, probably they didn’t include the fullchain.pem certificate in their TLS configuration.
1 Like