What are the conditions for challenges?

I believe the BR actually allows for reuse up to 398 days, but that's ridiculous (at least for these automated DV-only certificates) so Let's Encrypt's policies limit themselves to only 30 days. (And they're considering shortening that time significantly to make their compliance easier.)

Let's Encrypt does try to send a reminder email when there are 20 days left (so after 70 days), but really that's a last-ditch effort that tells you that your automation is broken. In a well-working system, your certificate would already be renewed or you'd be getting alerts from your automation that it's failing well before then.

5 Likes