# Trouble with renewal

**URL:** <https://community.letsencrypt.org/t/trouble-with-renewal/131611>\
**Category:** Help\
**Created:** [August 20, 2020, 4:20pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611 "2020-08-20T16:20:05Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![StanYork](https://avatars.discourse-cdn.com/v4/letter/s/919ad9/32.png) [@StanYork](https://community.letsencrypt.org/u/StanYork)\
**Post date:** [August 20, 2020, 4:20pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/1 "2020-08-20T16:20:06Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [ettransport.com](http://ettransport.com)

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot):

---

<div class="post-metadata">

**Author:** ![StanYork](https://avatars.discourse-cdn.com/v4/letter/s/919ad9/32.png) [@StanYork](https://community.letsencrypt.org/u/StanYork)\
**Post date:** [August 20, 2020, 4:26pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/2 "2020-08-20T16:26:44Z")

</div>

I had an employee who created my website and set us up with this certificate. He is now gone and I have no idea how to renew it. Help!

---

<div class="post-metadata">

**Author:** ![freessltools.com](https://avatars.discourse-cdn.com/v4/letter/f/cdc98d/32.png) [@freessltools.com](https://community.letsencrypt.org/u/freessltools.com)\
**Post date:** [August 20, 2020, 5:55pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/3 "2020-08-20T17:55:16Z")

</div>

Welcome. 🙂

I’ll try to help you out. Looking at the history of certificates for [ettransport.com](http://ettransport.com), I can see that you have 2 unexpired Let’s Encrypt certificates that have been automatically renewing every 60 days as normal:

- [ettransport.com](http://ettransport.com) and [www.ettransport.com](http://www.ettransport.com)
- [dev.ettransport.com](http://dev.ettransport.com)

Your domain registration with GoDaddy for [ettransport.com](http://ettransport.com) is set to expire at 17:30:33 UTC on 9/12/2020, but might be set up for automatic renewal. I’m not sure about the expiration status for the hosting of your website.

It looks like [ettransport.com](http://ettransport.com) and [www.ettransport.com](http://www.ettransport.com) are still serving a certificate that expired on 8/4 even though a new certificate was generated that expires on 10/3. Similarly, [dev.ettransport.com](http://dev.ettransport.com) is still serving a certificate that expired on 7/8 even though 2 new certificates were generated that expire on 9/6 and 11/5.

Did you recently change server setups for your website?

[https://crt.sh/?q=ettransport.com](https://crt.sh/?q=ettransport.com)

 ![Screenshot_20200820-115107_Samsung Internet](https://global.discourse-cdn.com/letsencrypt/original/3X/8/a/8a175bae91f13ba6a789c0d821990f416e7ff1da.jpeg)

---

<div class="post-metadata">

**Author:** ![StanYork](https://avatars.discourse-cdn.com/v4/letter/s/919ad9/32.png) [@StanYork](https://community.letsencrypt.org/u/StanYork)\
**Post date:** [August 21, 2020, 12:45pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/4 "2020-08-21T12:45:20Z")

</div>

Thanks so much for responding!

It is within the last two years that we had an employee create a new web site for us. I am not sure what the “[dev.ettransport.com](http://dev.ettransport.com)” would be, or why we would need 2 certificates, I am very inexperienced at this. All I know is that we have been using and advertising our [www.ettransport.com](http://www.ettransport.com) website for years and now folks cannot log into it without getting security warnings, as the certificate has expired. And I am also not sure why it would not have simply automatically renewed.

The employee who set up everything is no longer working here and I cannot reach him, I am thinking he may have possibly received some type of renewal notice in his emails but i have not been able to find it. I know the Go Daddy domain registration is set to automatically renew.

How would I determine if he changed server setups when creating the website?

Sorry to be such a novice…

Stan

---

<div class="post-metadata">

**Author:** ![freessltools.com](https://avatars.discourse-cdn.com/v4/letter/f/cdc98d/32.png) [@freessltools.com](https://community.letsencrypt.org/u/freessltools.com)\
**Post date:** [August 21, 2020, 5:58pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/5 "2020-08-21T17:58:36Z")

</div>

You're very welcome. 🙂

I know this kind of knowledge gap can be challenging when someone leaves. Let's try to tackle things one at a time and see where we arrive.

> [@StanYork](#):
>
> I am not sure what the “[dev.ettransport.com](http://dev.ettransport.com)” would be, or why we would need 2 certificates

I am not sure of what [dev.ettransport.com](http://dev.ettransport.com) would be either, but it currently returns a server error. Based on the "dev" it's possible this could have been used as a sandbox for a copy to safely develop/update the website without affecting the main operation of the website. This would explain why it returns an error, which is not the best situation, but should only be a wart that shouldn't affect anything. The separate certificate in this case is actually wise because it further divorces the operational (production) website from the development site and allows the development site to be hosted on an entirely separate server.

> [@StanYork](#):
>
> we have been using and advertising our [www.ettransport.com](http://www.ettransport.com) website for years and now folks cannot log into it without getting security warnings, as the certificate has expired. And I am also not sure why it would not have simply automatically renewed.

Referencing the information I provided in my first response, renewal certificates were issued, but evidently not installed. Considering that the website is still operational and to your knowledge the website was not moved to a different host, it is my guess that either the renewal process is requiring manual installation of the certificates or there is a configuration problem with installing the new certificates (which is unlikely given the substantial renewal history). There is also the possibility that the webserver simply needs to be restarted once the new certificates have been installed and the renewal process was unable to do so automatically. Therefore, I would suggest doing the following:

1. Restart the webserver.
2. Install the already-valid certificate you (should) have along with its corresponding private key.

I understand that you might not know how to accomplish these tasks. To help you with this, you'll need to gather more information about your webserver hosting including the name of the hosting provider and what ACME client is managing your certificates (I'm guessing it's certbot).

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [August 21, 2020, 10:23pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/6 "2020-08-21T22:23:28Z")

</div>

> [@freessltools.com](#):
>
> I understand that you might not know how to accomplish these tasks. To help you with this, you’ll need to gather more information about your webserver hosting including the name of the hosting provider and what ACME client is managing your certificates (I’m guessing it’s certbot).

I bet it's DigitalOcean for hosting provider, Nginx for web server, and probably certbot for certificate management.

---

<div class="post-metadata">

**Author:** ![freessltools.com](https://avatars.discourse-cdn.com/v4/letter/f/cdc98d/32.png) [@freessltools.com](https://community.letsencrypt.org/u/freessltools.com)\
**Post date:** [August 21, 2020, 10:26pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/7 "2020-08-21T22:26:26Z")

</div>

> [@stevenzhu](#):
>
> I bet it’s DigitalOcean for hosting provider, Nginx for web server, and probably certbot for certificate management.

My hat's off to you for discovering/deducing the first two. 😄 I didn't dig quite that deep. Probably should have though.

It's so rare to see an operational system that's successfully autorenewing, but not successfully installing new certificates. I'm really wondering what's going on.

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [August 21, 2020, 10:28pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/8 "2020-08-21T22:28:20Z")

</div>

To be honest, i think this might be another “Failed to reload Nginx issue”. It might be either the reload was done by hand before or there’s some issue with the current nginx configuration.

---

<div class="post-metadata">

**Author:** ![freessltools.com](https://avatars.discourse-cdn.com/v4/letter/f/cdc98d/32.png) [@freessltools.com](https://community.letsencrypt.org/u/freessltools.com)\
**Post date:** [August 21, 2020, 10:29pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/9 "2020-08-21T22:29:43Z")

</div>

I concur. I really hope it’s just a reload that’s needed.

---

<div class="post-metadata">

**Author:** ![StanYork](https://avatars.discourse-cdn.com/v4/letter/s/919ad9/32.png) [@StanYork](https://community.letsencrypt.org/u/StanYork)\
**Post date:** [August 24, 2020, 12:09pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/10 "2020-08-24T12:09:07Z")

</div>

I know that it IS Digital Ocean that is our hosting provider. I am not sure if Nginx is the web server, or how to find that out. Would the people at Digital Ocean be able to help me at this point?

---

<div class="post-metadata">

**Author:** ![freessltools.com](https://avatars.discourse-cdn.com/v4/letter/f/cdc98d/32.png) [@freessltools.com](https://community.letsencrypt.org/u/freessltools.com)\
**Post date:** [August 24, 2020, 12:27pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/11 "2020-08-24T12:27:54Z")

</div>

Just try running the following command to reload the webserver:

`sudo systemctl reload nginx`

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [August 24, 2020, 1:03pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/12 "2020-08-24T13:03:42Z")

</div>

> [@StanYork](#):
>
> Would the people at Digital Ocean be able to help me at this point?

Sadly, no. Your droplet at DigitalOcean is self-managed, which means the support team will be responsible for any hardware failures that occurred but not any software issues on your droplet.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 23, 2020, 1:03pm UTC](https://community.letsencrypt.org/t/trouble-with-renewal/131611/13 "2020-09-23T13:03:53Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
