Hi @ngrootjen,
Thank you for posting this, it saved me a lot of time today, trying to fix our legacy system :D
We had to do the following, which is a bit different from your commands:
We realized with
openssl x509 -in /opt/psa_agent/internal/rootchain.pem -text | grep 'Not After :'
on our...