SSL certificates limit reached for.. Even after 10 days


#1

My domain is: impacthub.net

I ran this command: rwssl -a

It produced this output:
Finding apps…
1 apps found in total. Proceeding further…
Obtaining SSL certificate for the app malaga.
2 valid domains found for the app
SSL certificates limit reached for malaga.impacthub.net www.malaga.impacthub.net. Please wait before obtaining another SSL.

My web server is (include version): PHP 7.2

The operating system my web server runs on is (include version): 16.04

My hosting provider, if applicable, is: Digital ocean/Server Pilot

I can login to a root shell on my machine (yes or no, or I don’t know): Yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): No

Hello Folks, not sure what is happening I a have been using the new script for past few weeks and since last Wednesday we haven’t installed any SLLs and I am still getting the error with “SSL certificates limit reached for … Please wait before obtaining another SSL”. Now20 domains per week is plenty for our usage is there some other limit that we are hitting or there is something I well need to change?

Thanks
Nikola


#2

It seems like you had a lot of renewals go through a bit under a week ago.

While renewals are not blocked by the weekly rate limits, they do contribute to them, preventing non-renewals from being issuable.

Edit: you should be able to issue a new certificate pretty much right now, or very soon.


#3

Hey thanks for the awesomely fast reply,

So not sure I understand this part

So the order matters, if I renew 20 I won’t be able to add 5 new SSLs, but if I add 5 new SSLs then I will be able to renew any number?

And is there a way to view the number of SSLs that are issued or I need to track it manually
Thanks
Nikola


#4

If you take a look at https://tools.letsdebug.net/cert-search?m=domain&q=impacthub.net&d=744 (or lookup your domain on crt.sh), you can see that you issued some ~150 certificates just over 7 days ago (on ~July 15th). These interfaces will have a delay of an hour or two, usually.

Yes, you have the right idea. The best way to maximize the number of certificates is to issue all of the new certificates first (up to 20), and then do renewals afterwards (no limit on those).


#5

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.