📚 node [[let s encrypt certificate renewal issue]]
Welcome! Nobody has contributed anything to 'let s encrypt certificate renewal issue' yet. You can:
  • Write something in the document below!
    • There is at least one public document in every node in the Agora. Whatever you write in it will be integrated and made available for the next visitor to read and edit.
  • Write to the Agora from social media.
    • If you follow Agora bot on a supported platform and include the wikilink [[let s encrypt certificate renewal issue]] in a post, the Agora will link it here and optionally integrate your writing.
  • Sign up as a full Agora user.
    • As a full user you will be able to contribute your personal notes and resources directly to this knowledge commons. Some setup required :)
⥅ related node [[lets encrypt certificate renewal issue]]
⥅ node [[lets-encrypt-certificate-renewal-issue]] pulled by Agora

Let's Encrypt certificate renewal issue

I got an email that my certificates were going to expire.

Given they are set to auto-renew, this seemed odd.

I logged in to the server and some errors indeed in ~/var/log/letsencrypt/letsencrypt.log

Along the lines of

Detail: 37.218.246.201: Fetching http://commonplace.doubleloop.net/.well-known/acme-challenge/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx: Timeout during connect (likely firewall problem)

And indeed it was a firewall problem. I did not have port 80 open, just 443 and some others.

ufw allow http
certbot -q renew

sorted it.

Weird that this just manifested though. What changed?

📖 stoas
⥱ context