Let's Encrypt says cert is good, Windows is saying it's expired

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: tampahybrids.online

I ran this command: Using WinAcme, I just forced a renewal (regular renewal process was not working, but force did).

It produced this output:

My web server is (include version): IIS v10

The operating system my web server runs on is (include version): Windows Server 2019 Standard

My hosting provider, if applicable, is: nfoservers.com

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): No, using WinAcme.

If I go into MMC and look at personal certificates, I see two for tampahybrids.online, but the most recent one expired 12-Sept-2024. But using WinAcme and showing the certificate detail, I see that the renewal is not due until 13-Nov-2024. It shows green in the output, signaling it's ok (I do have one that's red, but not this one).

What does Windows say exactly? Please mention or show as much info as possible.

2 Likes

Here are the only two certs recorded for that FQDN:
image
Based on that, it seems the first cert wasn't yet due to be renewed.
Which would explain why it wasn't renewed and why a forced renewal did obtain a new cert.

FYI: LE certs are valid for 90 days and most ACME clients auto renew after 60 days of use.

5 Likes

WinAcme showed the renewal as having failed. Before I did anything. I have the auto-renewal task set up. I thought I had email notification set up, but don't, so I will have to do that. Anyway, I was able to find the certificates and import the one in question and also add it to some other software I'm using and now - glory be! :slight_smile: - my problems are solved. That one, at least. Thank you for your reply.

3 Likes

Osiris - Not sure of the details with this forum software. Just wanted to make sure you saw the previous reply to rg305. Got things worked out. Thank you for your help.

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.