How to generate renewal certificates will expire


#1

Hello!

I got mail that these certificates will expire



static.kassakaappi.net
template.kassakaappi.net
www.kassakaappi.net

So I run: /root/certbot-auto renew
this does not help with these problem.

I got: /etc/letsencrypt/renewal
only this with kassakaappi
www.kassakaappi.net.conf

Other websites I got these files
x.fi.conf
static.x.fi.conf
template.x.fi.conf

And other websites working ok.

So what I do that I can have these files too with kassakaappi ?

Here: /etc/apache2/sites-available
Other sites
x.conf
x-le-ssl.conf
static.x.conf
static.x-le-ssl.conf
template.conf
template.x-le-ssl.conf

And kassakaappi:

kassakaappi.conf
kassakaappi-le-ssl.conf
template.kassakaappi.conf
template.kassakaappi-le-ssl.conf
static.kassakaappi.conf
static.kassakaappi-le-ssl.conf

But inside these files other *le-ssl.conf files end like this

example: eco-toimistotatvikkeet-le-ssl.conf

SSLCertificateFile /etc/letsencrypt/live/hiekkalaatikko.eco-toimistotarvikkeet.fi/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/hiekkalaatikko.eco-toimistotarvikkeet.fi/privkey.pem
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateChainFile /etc/letsencrypt/live/hiekkalaatikko.eco-toimistotarvikkeet.fi/chain.pem

example: template.eco-toimistotatvikkeet-le-ssl.conf

SSLCertificateFile /etc/letsencrypt/live/template.eco-toimistotarvikkeet.fi/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/template.eco-toimistotarvikkeet.fi/privkey.pem
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateChainFile /etc/letsencrypt/live/template.eco-toimistotarvikkeet.fi/chain.pem

But all kassakaappi *.le-ssl.conf files

kassakaappi-le-ssl.conf
template.kassakaappi-le-ssl.conf
static.kassakaappi-le-ssl.conf

end like this:

SSLCertificateFile /etc/letsencrypt/live/www.kassakaappi.net/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/www.kassakaappi.net/privkey.pem
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateChainFile /etc/letsencrypt/live/www.kassakaappi.net/chain.pem

So how I can get that template.kassakaappi static.kassakaappi
get /etc/letsencrypt/live/ those certificates?

Or is this one /etc/letsencrypt/live/www.kassakaappi.net/chain.pem
enough for these sites:



static.kassakaappi.net
template.kassakaappi.net
www.kassakaappi.net

What should I do ? To get certificates for these sites?Or do I do it afterall ?
Is there everything allright?

Yours Timo


#2

Your sites certificates were renewed on the 8th Oct, there is nothing you need to do, everything looks OK.


#3

Thank you for your answer! I just wonder why I got this mail:

"Your certificate (or certificates) for the names listed below will expire in 10 days (on 25 Oct 16 07:14 +0000). Please make sure to renew your certificate before then, or visitors to your website will encounter errors.



static.kassakaappi.net
template.kassakaappi.net
www.kassakaappi.net"

Are listed sites too working after 25 Oct 16 ?
Other sites which I do not mention works after that
but what about those listed sites?


#4

You got the email because in July you obtained a cert for

DNS:hiekkalaatikko.kassakaappi.net
DNS:kassakaappi.net
DNS:static.kassakaappi.net
DNS:template.kassakaappi.net
DNS:www.kassakaappi.net

This certificate from July is due for renewal, however you have obtained a different certificate in August for;

hiekkalaatikko.eco-toimistotarvikkeet.fi
hiekkalaatikko.kassakaappi.net
hiekkalaatikko.proficient.fi
kassakaappi.net
proficient.fi
static.eco-toimistotarvikkeet.fi
static.kassakaappi.net
static.proficient.fi
template.eco-toimistotarvikkeet.fi
template.kassakaappi.net
template.proficient.fi
vanha.kassakaappi.net
www.eco-toimistotarvikkeet.fi
www.kassakaappi.net
www.proficient.fi

Since this second certificate was not a renewal, but a new certificate, the system is telling you that the original one is due for renewal, in reality though you have all the domain names covered on a different certificate, which you have renewed (8th October)


#5

Thank you very much! for your answer.
It’s clear now.


#6

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.