Screwed up key-type

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: douganconsulting.com

I ran this command:

certbot certonly --key-type rsa --manual  --expand --preferred-challenges dns-01 -d *.douganconsulting.com,douganconsulting.com,*.douganfamily.org,*.intelligenttechnology.ca,*.teresadougan.com,*.vancouvershamrockcsc.org

It produced this output:

Error creating new order :: too many certificates (5) already issued for this exact set of domains in the last 168 hours

My web server is (include version): Apache 2.4.37

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is: N/A

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

No

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):

certbot 2.5.0


I somehow managed to run my renewal with the wrong key type and some of my other servers are having issues with it. When I realized where the issue lay, I ran certbot again with the --key-type parameter. However, because I'd been trying to run it after editing the conf file to change the key type to rsa there, I'm getting the too many certificate requests error. Is there anything I can do to resolve this?

Thanks.

1 Like

What shows?:
certbot certificates

3 Likes

You're getting:

Not exactly the same thing.

3 Likes

$ certbot certificates
Saving debug log to /var/log/letsencrypt/letsencrypt.log


Found the following certs:
Certificate Name: douganconsulting.com-0001
Serial Number: 39853c01cd95ad7780718aa6135f029a67f
Key Type: ECDSA
Domains: *.douganconsulting.com *.douganfamily.org *.intelligenttechnology.ca *.teresadougan.com *.vancouvershamrockcsc.org douganconsulting.com
Expiry Date: 2023-08-07 02:56:54+00:00 (VALID: 89 days)
Certificate Path: /etc/letsencrypt/live/douganconsulting.com-0001/fullchain.pem
Private Key Path: /etc/letsencrypt/live/douganconsulting.com-0001/privkey.pem
Certificate Name: douganconsulting.com
Serial Number: 4f9622d086c98beed752654db93455cbe24
Key Type: RSA
Domains: *.douganconsulting.com *.douganfamily.org *.intelligenttechnology.ca *.teresadougan.com *.vancouvershamrockcsc.org douganconsulting.com office.bungaylawoffice.ca
Expiry Date: 2023-06-11 23:47:58+00:00 (VALID: 33 days)
Certificate Path: /etc/letsencrypt/live/douganconsulting.com/fullchain.pem
Private Key Path: /etc/letsencrypt/live/douganconsulting.com/privkey.pem


The second cert contain all of the names on the first cert plus this one name:

If you don't need that extra name, then you can delete that cert:
certbot delete --cert-name douganconsulting.com
If you do need that name, then you need to delete the first cert and renew the second.

2 Likes

Thanks so much for your help. I've resolved it with your suggestion.

Regards,
Des

6 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.