# Issue with auto renew

**URL:** <https://community.letsencrypt.org/t/issue-with-auto-renew/155789>\
**Category:** Help\
**Created:** [July 15, 2021, 3:11pm UTC](https://community.letsencrypt.org/t/issue-with-auto-renew/155789 "2021-07-15T15:11:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![asmall](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@asmall](https://community.letsencrypt.org/u/asmall)\
**Post date:** [July 15, 2021, 3:11pm UTC](https://community.letsencrypt.org/t/issue-with-auto-renew/155789/1 "2021-07-15T15:11:31Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: baw.prod.ultramain.systems

I ran this command: No command ran I was expecting it to auto renew, When I run certbot renew it works fine but when it tries to do it automatically I get the ERROR:certbot.\_internal.renewal:Failed to renew certificate baw.prod.ultramain.systems with error: urn:ietf:params:acme:error:serverInternal :: The server experienced an internal error :: Error finalizing order

It produced this output: HTTP 500  
Content-Length: 112  
Cache-Control: public, max-age=0, no-cache  
Server: nginx  
Connection: keep-alive  
Link: [https://acme-staging-v02.api.letsencrypt.org/directory](https://acme-staging-v02.api.letsencrypt.org/directory);rel="index"  
Boulder-Requester: 11651561  
Date: Mon, 26 Apr 2021 18:11:49 GMT  
Content-Type: application/problem+json  
Replay-Nonce: 0004tn9OcyPdA23ztDQmnCoUav-\_\_7XvSOklxi4ceUnQGvg

{ "type": "urn:ietf:params:acme:error:serverInternal", "detail": "Error finalizing order", "status": 500 }

2021-04-26 18:11:49,080:ERROR:certbot.\_internal.renewal:Failed to renew certificate baw.prod.ultramain.systems with error: urn:ietf:params:acme:error:serverInternal :: The server experienced an internal error :: Error finalizing order  
2021-04-26 18:11:49,095:DEBUG:certbot.\_internal.renewal:Traceback was:  
Traceback (most recent call last):  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/renewal.py", line 471, in handle\_renewal\_request  
main.renew\_cert(lineage\_config, plugins, renewal\_candidate)  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/main.py", line 1235, in renew\_cert  
renewed\_lineage = \_get\_and\_save\_cert(le\_client, config, lineage=lineage)  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/main.py", line 124, in \_get\_and\_save\_cert  
renewal.renew\_cert(config, domains, le\_client, lineage)  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/renewal.py", line 331, in renew\_cert  
new\_cert, new\_chain, new\_key, \_ = le\_client.obtain\_certificate(domains, new\_key)  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/client.py", line 390, in obtain\_certificate  
cert, chain = self.obtain\_certificate\_from\_csr(csr, orderr)  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/client.py", line 292, in obtain\_certificate\_from\_csr  
fetch\_alternative\_chains=get\_alt\_chains)  
File "/usr/lib/python2.7/site-packages/acme/client.py", line 925, in finalize\_order  
return self.client.finalize\_order(orderr, deadline, fetch\_alternative\_chains)  
File "/usr/lib/python2.7/site-packages/acme/client.py", line 752, in finalize\_order  
self.\_post(orderr.body.finalize, wrapped\_csr)  
File "/usr/lib/python2.7/site-packages/acme/client.py", line 97, in \_post  
return self.net.post(\*args, \*\*kwargs)  
File "/usr/lib/python2.7/site-packages/acme/client.py", line 1201, in post  
return self.\_post\_once(\*args, \*\*kwargs)  
File "/usr/lib/python2.7/site-packages/acme/client.py", line 1214, in \_post\_once  
response = self.\_check\_response(response, content\_type=content\_type)  
File "/usr/lib/python2.7/site-packages/acme/client.py", line 1072, in \_check\_response  
raise messages.Error.from\_json(jobj)  
Error: urn:ietf:params:acme:error:serverInternal :: The server experienced an internal error :: Error finalizing order

2021-04-26 18:11:49,095:DEBUG:certbot.display.util:Notifying user:

- 
* * *

2021-04-26 18:11:49,095:ERROR:certbot.\_internal.renewal:All simulated renewals failed. The following certificates could not be renewed:  
2021-04-26 18:11:49,095:ERROR:certbot.\_internal.renewal: /etc/letsencrypt/live/baw.prod.ultramain.systems/fullchain.pem (failure)  
2021-04-26 18:11:49,095:DEBUG:certbot.display.util:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -  
2021-04-26 18:11:49,097:INFO:certbot.compat.misc:Running post-hook command: systemctl restart nginx  
2021-04-26 18:11:49,277:DEBUG:certbot.\_internal.log:Exiting abnormally:  
Traceback (most recent call last):  
File "/bin/certbot", line 9, in   
load\_entry\_point('certbot==1.11.0', 'console\_scripts', 'certbot')()  
File "/usr/lib/python2.7/site-packages/certbot/main.py", line 15, in main  
return internal\_main.main(cli\_args)  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/main.py", line 1421, in main  
return config.func(config, plugins)  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/main.py", line 1318, in renew  
renewal.handle\_renewal\_request(config)  
File "/usr/lib/python2.7/site-packages/certbot/\_internal/renewal.py", line 497, in handle\_renewal\_request  
len(renew\_failures), len(parse\_failures)))  
Error: 1 renew failure(s), 0 parse failure(s)  
2021-04-26 18:11:49,278:ERROR:certbot.\_internal.log:1 renew failure(s), 0 parse failure(s)

My web server is (include version): Nginx 1.20.0

The operating system my web server runs on is (include version): Linux baw-prod-primary 4.14.232-176.381.amzn2.x86\_64 #1 SMP Wed May 19 00:31:54 UTC 2021 x86\_64 x86\_64 x86\_64 GNU/Linux

My hosting provider, if applicable, is: AWS

I can login to a root shell on my machine (yes or no, or I don't know):Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):No

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):certbot 1.11.0

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [July 15, 2021, 5:32pm UTC](https://community.letsencrypt.org/t/issue-with-auto-renew/155789/2 "2021-07-15T17:32:37Z")

</div>

> [@asmall](#):
>
> Error: urn:ietf:params:acme:error:serverInternal :: The server experienced an internal error :: Error finalizing order

Internal errors are usually due to _some kind_ of hick-up at the Let's Encrypts systems. I'm not seeing any recent disturbance, so maybe you were just unlucky.

Could you try again and see if it works this time?

Also: is your server really having April 26 as the current date? Or are you showing us a very old log?

---

<div class="post-metadata">

**Author:** ![asmall](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@asmall](https://community.letsencrypt.org/u/asmall)\
**Post date:** [July 15, 2021, 7:36pm UTC](https://community.letsencrypt.org/t/issue-with-auto-renew/155789/3 "2021-07-15T19:36:51Z")

</div>

Hi Osiris,

So that is actually the only error that I found in my logs but our cert was set to expire in 5 days from now and it never auto renewed. When I went back into the logs that is the only error that I could find but the dates lined up since the cert only lasts for 90 days. Once I ran the command manually certbot renew I did not have any issues getting a new cert but if I don't run the command certbot will not renew on its own for some reason.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [July 15, 2021, 8:16pm UTC](https://community.letsencrypt.org/t/issue-with-auto-renew/155789/4 "2021-07-15T20:16:58Z")

</div>

> [@asmall](#):
>
> Once I ran the command manually certbot renew I did not have any issues getting a new cert but if I don't run the command certbot will not renew on its own for some reason.

Depending on how you've installed certbot, there might or might _not_ have been a cronjob or systemd timer installed. Usually, one would run `certbot renew` twice a day through such a cronjob or systemd timer.

---

<div class="post-metadata">

**Author:** ![asmall](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@asmall](https://community.letsencrypt.org/u/asmall)\
**Post date:** [July 21, 2021, 3:49pm UTC](https://community.letsencrypt.org/t/issue-with-auto-renew/155789/5 "2021-07-21T15:49:07Z")

</div>

@Osiris I plan to uninstall my current version of certbot 1.11.0 and update to the latest version and see if that helps.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [August 20, 2021, 3:49pm UTC](https://community.letsencrypt.org/t/issue-with-auto-renew/155789/6 "2021-08-20T15:49:14Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
