Can't renew, expired?

Maybe I have to ask one by one. I’ve been trying to renew one certificate, for the 5 whole days or so, applying many many different configurations of web server (http) (and firewall, name server, local configurations, etc.).

  1. the question was: when renewing, what permissions is the web server required to be given? But I just read a recent post where I see that even a web server is not required when renewing and that’s confusing to me. It is “http-01” challenge type and so I use the same method, local web server, but whatever configuration I apply, I gets “authorizations for these names not found or expired, status: 403”
    (I placed a html file every directory/path down to the acme-challenge directory and made sure all accessible.)
    So this question (as well) seems getting back to how the renew differ exactly from the first creation.

  2. I’m also confusing: expiration date for the renew itself. Is it the same as the certificate itself expiration date, or 30 (or 60) days before the certificate expiration? The certificate, I’m trying to renew, itself expires in 5 days.

Please provide more information.

It should be exactly the same.

Likely something has changed, or is going wrong. :slightly_frowning_face:

It depends on the ACME client and its configuration. It's common to start trying to renew a certificate 30 days before it expires, but clients can do anything (subject to the rate limits).

Thank you for your reply, mnordhoff.

Would you mean Letsencrypt client configuration or web server configuration, or? The web server configuration on the certificate creation had very basic configuration, without specifying even the domain name.

To be sure, I just tried once again to renew it with the exactly same configurations as advised, but it failed with the same error I stated above.
If the "machine" name has changed since the certificate creation, could that be a problem?

That seems why I've felt it discussed differently. The man page for the client I use says "If the certificate already exists and is less than 30 days from expiry, acme-client will attempt to refresh the signature.acme-client(1) - OpenBSD manual pages" In this case one can "renew" till 0 day from expiry, right?
What one can/should do after the expiry, if wants to continue to use the certificate or at least a new one again from Letsencrypt?

