--issue --force vs. --renew --force

I'm not that familiar with to know the exact difference in behaviour between --issue and --renew, but the only reason to use --force in either situations would be to update the properties of an existing certificate, e.g. adding or removing the "must staple" option or its key type.


Thank you


The only safe way to understand that difference is to go and study source code. It's not a massively long code but it takes a while to understand where to look for what.

As for

not with, there is no --dry-run and trying to use the staging endpoint might be unsafe if you have a production certificate (backup, backup, backup)


