Error creating new cert :: too many certificates already issued

Please fill out the fields below so we can help you better.

My domain is: beharmony.net

I ran this command: no command - I used ISPmanager letsencrypt module

It produced this output: return code:429
Details:Error creating new cert :: too many certificates already issued for exact set of domains: beharmony.net,www.beharmony.net

My web server is (include version): Apache/2.4.18

The operating system my web server runs on is (include version): 16.04.1-Ubuntu

My hosting provider, if applicable, is: Hetzner

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): ISPmanager Lite 5.106.1

Looks like my panel due to some bug, couldn’t save a certificate. I’ll try to do everything manually, so I kindly ask you to raise the limits to my domain so I could di everything without waiting for 7 days.

Thanks!

Hi @must2die,

You have reached this limit (you can check the rate limits here Rate Limits - Let's Encrypt) :

We also have a Duplicate Certificate limit of 5 certificates per week. A certificate is considered a duplicate of an earlier certificate if they contain the exact same set of hostnames, ignoring capitalization and ordering of hostnames. For instance, if you requested a certificate for the names [www.example.com, example.com], you could request four more certificates for [www.example.com, example.com] during the week. If you changed the set of names by adding [blog.example.com], you would be able to request additional certificates.

There is no procedure to remove or raise the limit so you have 3 options:

1.- If you have the private key you can get your certificate in this site https://censys.io/ and search for your domain (pressing the button search you need to click on Certificates). It take some time to appear the cert in that site and right now it is not available so would need to wait a few hours. Anyway, as you said that due to some issue the certs were not saved in your system I doubt you could have the private key.

2.- Add a new sub domain to your certificate, beharmony.net, www.beharmony.net and if you add for example blog.beharmony.net you will be able to issue a new certificate.

3.- If you want that your certificate only contain beharmony.net and www.beharmony.net yu MUST wait 7 days as you have reached the limit of certiticates per same subset of domains.

CRT ID     DOMAIN (CN)    VALID FROM              VALID TO                EXPIRES IN  SANs
143875472  beharmony.net  2017-May-25 07:29 CEST  2017-Aug-23 07:29 CEST  89 days     beharmony.net
                                                                                      www.beharmony.net

143873880  beharmony.net  2017-May-25 07:23 CEST  2017-Aug-23 07:23 CEST  89 days     beharmony.net
                                                                                      www.beharmony.net

143872294  beharmony.net  2017-May-25 07:17 CEST  2017-Aug-23 07:17 CEST  89 days     beharmony.net
                                                                                      www.beharmony.net

143869917  beharmony.net  2017-May-25 07:11 CEST  2017-Aug-23 07:11 CEST  89 days     beharmony.net
                                                                                      www.beharmony.net

143868094  beharmony.net  2017-May-25 07:05 CEST  2017-Aug-23 07:05 CEST  89 days     beharmony.net
                                                                                      www.beharmony.net

143866648  beharmony.net  2017-May-25 06:59 CEST  2017-Aug-23 06:59 CEST  89 days     beharmony.net
                                                                                      www.beharmony.net

Cheers,
sahsanu

2 Likes

Thanks for your reply. Ok, I’ll keep waiting.

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.