Some devices getting SSL Cert Expiry Notice but it is already renewed in the server

You might want to improve on whatever you might find.
It should be startightforward.
All systems able to use the new cert directly should do so via service reloads [or full reboot].
Anything beyond that could be improved upon.
OR if unable to do so easily can be included in a certificate --deploy-hook script.

4 Likes

Alright,
I've done a reload. Would a reboot be safe for postfix?
I will look into the script!

A reboot should be safe for any service, otherwise your server is reaaaallly messed up.

That said, I don't think it will do you any good, but it might help if there's some process "stuck", although I've never heard of that for Postfix. (It sometimes happens with Apache.)

My first think would be to check the Postfix configuration.

5 Likes

Will do!
Ran a check and I got a warning. Based on what I read does not seem to be linked to the issue but I will post it here regardless. I could be wrong.
warning: symlink leaves directory: /etc/postfix/./makedefs.out

I found a similar article on here after hours of searching and actually saw one of your old answers which fixed my problem too. I think this command needed to run after renewing but it wasn't.
postmap -F hash:/etc/postfix/sni_maps
It seemed to fix it.
Thank you so much for your help!

4 Likes

Thanks for sharing what worked for you, @erinam99.

4 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.