Certificate expiring before the expiration data

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: wallet.klubcoin.net

I ran this command: The certificate expired in around 30 days even though its lifetime was for 90 days and certbot docker container was configured to renew the cert when less than 30 days are left in cert expiration.

It produced this output:

My web server is (include version): nginx 1.15.12

The operating system my web server runs on is (include version): Linux version 5.13.0-52-generic

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): certbot 2.6.0

I am not quite sure what the problem is. You have gotten certs on a regular schedule although the latest was a little different.

You got two identical certs in both Jul and Sep (60 days apart). Were you intending to always get 2 identical certs? Because often that points to a problem but it can be valid in cases like small load balancers and such.

Then, you got just one cert "early" only 30 days later in Oct. And, this cert is currently being used by your server.

Can you explain more details of what you think went wrong?

5 Likes

Déjà vu: Letsencrypt ssl expired in 1 month

2 Likes

No it was not intended to use the 2 identical certs.. I am not sure why its so and how to resolve it

Yes I know about it

Usually (as in, almost always) it's not very helpful to have two threads for the same problem/issue/domain.

Can you provide any reason why this thread should continue in favor of the other one?

1 Like

It's by someone else from my team, I am asking her to close that and its was not very clear..

Can it also be due to certbot of particular version, like this one is certbot 2.6.0? How can I check on server for another cert because path /etc/nginx/ssl/live/wallet.klubcoin.net/cert.pem is the one I know and shows the correct expiry date..

Can someone please help here?

What is the problem?
I see a valid new cert in use:
SSL Server Test: wallet.klubcoin.net (Powered by Qualys SSL Labs)

3 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.