Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Let's Encrypt Didn't seem to auto-renew

Let's Encrypt Didn't seem to auto-renew

Scheduled Pinned Locked Moved Solved Support
letsencryptcertificates
39 Posts 17 Posters 9.9k Views 15 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • girishG girish

    @nj the logs thing is fixed in 7.3.5. Can you update and check?

    But there is still the underlying problem of certs not renewing sometimes with 7.3.

    jordanurbsJ Offline
    jordanurbsJ Offline
    jordanurbs
    wrote on last edited by
    #21

    Also having this issue for several domains on my cloudron.

    Manually renewing all certs, restarting apps, deleting browser cookies, nothing is fixing it.

    My cloudron is on Ubuntu 20

    1 Reply Last reply
    0
    • girishG Offline
      girishG Offline
      girish
      Staff
      wrote on last edited by
      #22

      Wanted to update this thread. We found the issue, we will make a release with a fix (7.3.6) asap.

      jaschaezraJ 1 Reply Last reply
      11
      • girishG girish

        Wanted to update this thread. We found the issue, we will make a release with a fix (7.3.6) asap.

        jaschaezraJ Offline
        jaschaezraJ Offline
        jaschaezra
        wrote on last edited by
        #23

        @girish Thank you! I just came to report the same issue and was delighted that already had been taking care of! Great work!

        1 Reply Last reply
        2
        • girishG Offline
          girishG Offline
          girish
          Staff
          wrote on last edited by
          #24

          7.3.6 is out now which should fix this, rolling out slowly.

          humptydumptyH 1 Reply Last reply
          0
          • girishG girish marked this topic as a question on
          • girishG girish has marked this topic as solved on
          • girishG girish

            7.3.6 is out now which should fix this, rolling out slowly.

            humptydumptyH Offline
            humptydumptyH Offline
            humptydumpty
            wrote on last edited by humptydumpty
            #25

            @girish I know updates are rolled out alphabetically but is it based on the installed subdomain (ex: rambo.domain.com) or the bare domain?

            girishG 1 Reply Last reply
            0
            • humptydumptyH humptydumpty

              @girish I know updates are rolled out alphabetically but is it based on the installed subdomain (ex: rambo.domain.com) or the bare domain?

              girishG Offline
              girishG Offline
              girish
              Staff
              wrote on last edited by girish
              #26

              @humptydumpty iirc, it's on the primary domain i.e installed subdomain.

              jdaviescoatesJ 1 Reply Last reply
              1
              • girishG girish

                @humptydumpty iirc, it's on the primary domain i.e installed subdomain.

                jdaviescoatesJ Offline
                jdaviescoatesJ Offline
                jdaviescoates
                wrote on last edited by
                #27

                @girish that isn't very clear! 😛

                I think it's surely based on the domain name used for my.domain.tld, no?

                i.e.

                my.aaaaa.tld gets updated before
                my.bbbbb.tld
                ....
                my.zzzzz.tld

                That's been my experience anyway.

                I use Cloudron with Gandi & Hetzner

                girishG 1 Reply Last reply
                0
                • jdaviescoatesJ jdaviescoates

                  @girish that isn't very clear! 😛

                  I think it's surely based on the domain name used for my.domain.tld, no?

                  i.e.

                  my.aaaaa.tld gets updated before
                  my.bbbbb.tld
                  ....
                  my.zzzzz.tld

                  That's been my experience anyway.

                  girishG Offline
                  girishG Offline
                  girish
                  Staff
                  wrote on last edited by
                  #28

                  @jdaviescoates yes, that's the primary domain in cloudron terminology

                  jordanurbsJ 1 Reply Last reply
                  0
                  • girishG girish

                    @jdaviescoates yes, that's the primary domain in cloudron terminology

                    jordanurbsJ Offline
                    jordanurbsJ Offline
                    jordanurbs
                    wrote on last edited by jordanurbs
                    #29

                    @girish I've still got problems after updating.

                    I'm assuming a manual certificate is my only option from here

                    girishG 1 Reply Last reply
                    0
                    • jordanurbsJ jordanurbs

                      @girish I've still got problems after updating.

                      I'm assuming a manual certificate is my only option from here

                      girishG Offline
                      girishG Offline
                      girish
                      Staff
                      wrote on last edited by
                      #30

                      @jordanurbs what problem are you facing exactly? Click on the renew all button and post the logs, please.

                      1 Reply Last reply
                      0
                      • matix131997M Offline
                        matix131997M Offline
                        matix131997
                        wrote on last edited by
                        #31

                        Hello,

                        I also report a problem with the certificate having on the domain yyy.xxx.tld
                        I noticed that the problem is common in many browsers - Firefox, Chrome, Brave and Vivaldi on the computer - the error pops up, and on Edge there is no error. On mobile devices - there is an error on all browsers.

                        Feb 03 10:18:41 box:tasks update 15: {"percent":51,"message":"Ensuring certs of my.yyy.xxx.tld"}
                        Feb 03 10:18:41 box:reverseproxy providerMatchesSync: subject=CN = *.yyy.xxx.tld domain=*.yyy.xxx.tld issuer=C = US, O = Let's Encrypt, CN = R3 wildcard=true/true prod=true/true issuerMismatch=false wildcardMismatch=false match=true
                        Feb 03 10:18:41 box:reverseproxy expiryDate: subject=CN = *.yyy.xxx.tld notBefore=Feb 2 16:20:50 2023 GMT notAfter=May 3 16:20:49 2023 GMT daysLeft=89.2931378587963
                        Feb 03 10:18:41 box:reverseproxy needsRenewal: false. force: false
                        Feb 03 10:18:41 box:reverseproxy ensureCertificate: my.yyy.xxx.tld acme cert exists and is up to date
                        
                        girishG 1 Reply Last reply
                        0
                        • matix131997M matix131997

                          Hello,

                          I also report a problem with the certificate having on the domain yyy.xxx.tld
                          I noticed that the problem is common in many browsers - Firefox, Chrome, Brave and Vivaldi on the computer - the error pops up, and on Edge there is no error. On mobile devices - there is an error on all browsers.

                          Feb 03 10:18:41 box:tasks update 15: {"percent":51,"message":"Ensuring certs of my.yyy.xxx.tld"}
                          Feb 03 10:18:41 box:reverseproxy providerMatchesSync: subject=CN = *.yyy.xxx.tld domain=*.yyy.xxx.tld issuer=C = US, O = Let's Encrypt, CN = R3 wildcard=true/true prod=true/true issuerMismatch=false wildcardMismatch=false match=true
                          Feb 03 10:18:41 box:reverseproxy expiryDate: subject=CN = *.yyy.xxx.tld notBefore=Feb 2 16:20:50 2023 GMT notAfter=May 3 16:20:49 2023 GMT daysLeft=89.2931378587963
                          Feb 03 10:18:41 box:reverseproxy needsRenewal: false. force: false
                          Feb 03 10:18:41 box:reverseproxy ensureCertificate: my.yyy.xxx.tld acme cert exists and is up to date
                          
                          girishG Offline
                          girishG Offline
                          girish
                          Staff
                          wrote on last edited by
                          #32

                          @matix131997 have you tried domains -> renew all certs already?

                          matix131997M 1 Reply Last reply
                          0
                          • girishG girish

                            @matix131997 have you tried domains -> renew all certs already?

                            matix131997M Offline
                            matix131997M Offline
                            matix131997
                            wrote on last edited by
                            #33

                            @girish Yes

                            girishG 1 Reply Last reply
                            0
                            • matix131997M matix131997

                              @girish Yes

                              girishG Offline
                              girishG Offline
                              girish
                              Staff
                              wrote on last edited by
                              #34

                              @matix131997 per the logs atleast, the certs are fine (from yesterday)

                              Feb 03 10:18:41 box:reverseproxy expiryDate: subject=CN = *.yyy.xxx.tld notBefore=Feb 2 16:20:50 2023 GMT notAfter=May 3 16:20:49 2023 GMT daysLeft=89.2931378587963
                              

                              Have you tried clearing the browser cache? If you like, you can also send us the domain to support@cloudron.io and we can check on our end.

                              matix131997M 2 Replies Last reply
                              0
                              • girishG girish

                                @matix131997 per the logs atleast, the certs are fine (from yesterday)

                                Feb 03 10:18:41 box:reverseproxy expiryDate: subject=CN = *.yyy.xxx.tld notBefore=Feb 2 16:20:50 2023 GMT notAfter=May 3 16:20:49 2023 GMT daysLeft=89.2931378587963
                                

                                Have you tried clearing the browser cache? If you like, you can also send us the domain to support@cloudron.io and we can check on our end.

                                matix131997M Offline
                                matix131997M Offline
                                matix131997
                                wrote on last edited by matix131997
                                #35

                                @girish Yes these are the certificates issued yesterday, because I put the server back up last night to move the applications from the old server. It was fine with the certificate until this morning. At work, the certificate started failing. I did a certificate refresh several times, cleared the browser and tests on several office devices and the error continues to appear.

                                EDIT: Now I reinstalled Cloudron but with manual settings for the domain with a Polish provider and it works fine so far. The certificate generates and displays without error. We will see in a few hours.

                                1 Reply Last reply
                                1
                                • girishG girish

                                  @matix131997 per the logs atleast, the certs are fine (from yesterday)

                                  Feb 03 10:18:41 box:reverseproxy expiryDate: subject=CN = *.yyy.xxx.tld notBefore=Feb 2 16:20:50 2023 GMT notAfter=May 3 16:20:49 2023 GMT daysLeft=89.2931378587963
                                  

                                  Have you tried clearing the browser cache? If you like, you can also send us the domain to support@cloudron.io and we can check on our end.

                                  matix131997M Offline
                                  matix131997M Offline
                                  matix131997
                                  wrote on last edited by matix131997
                                  #36

                                  @girish
                                  I seem to have found the cause. It is probably related to the API of the domain providers. I did a test with 3 providers.

                                  Hetzner DNS - no problem
                                  GoDaddy - problem
                                  Manual (domeny.tv) - no problem

                                  EDIT: Sorry for the edit. 😂 One more test I did I used the domain that is in GoDaddy, having my.yyy.xxx-xxx.tld for manual settings. An error appears with the certificate! I have a feeling it's a problem with GoDaddy DNS or by the "-" in the domain.

                                  jdaviescoatesJ 1 Reply Last reply
                                  1
                                  • matix131997M matix131997

                                    @girish
                                    I seem to have found the cause. It is probably related to the API of the domain providers. I did a test with 3 providers.

                                    Hetzner DNS - no problem
                                    GoDaddy - problem
                                    Manual (domeny.tv) - no problem

                                    EDIT: Sorry for the edit. 😂 One more test I did I used the domain that is in GoDaddy, having my.yyy.xxx-xxx.tld for manual settings. An error appears with the certificate! I have a feeling it's a problem with GoDaddy DNS or by the "-" in the domain.

                                    jdaviescoatesJ Offline
                                    jdaviescoatesJ Offline
                                    jdaviescoates
                                    wrote on last edited by
                                    #37

                                    @matix131997 said in Let's Encrypt Didn't seem to auto-renew:

                                    GoDaddy,

                                    Sounds like yet another reason to avoid GoDaddy like the plague 🤢

                                    I use Cloudron with Gandi & Hetzner

                                    1 Reply Last reply
                                    1
                                    • H Offline
                                      H Offline
                                      henry000
                                      wrote on last edited by henry000
                                      #38

                                      In my case, my certificate failed because when Let's Encrypt was trying to confirm the TXT records with my domain manager, Digital Ocean, and for some reason, the TXT record content had double-quotes around them. So I had to login to Digital Ocean, find the TXT record, and updated it by removing the double-quotes at start and end.

                                      I found out this by logging into my Cloudron dashboard - which is expired - using a browser that allowed me to do that. Once I logged in to the dashboard, I renewed the certificate manually. While it was failing (due to extra double-quotes), I opened the log and inspected it, and was able to see that the double-quotes were causing the issue.

                                      1 Reply Last reply
                                      1
                                      • girishG Offline
                                        girishG Offline
                                        girish
                                        Staff
                                        wrote on last edited by
                                        #39

                                        @henry000 the problem is already fixed in 7.6. Are you on Cloudron 7.6 ?

                                        1 Reply Last reply
                                        1
                                        Reply
                                        • Reply as topic
                                        Log in to reply
                                        • Oldest to Newest
                                        • Newest to Oldest
                                        • Most Votes


                                        • Login

                                        • Don't have an account? Register

                                        • Login or register to search.
                                        • First post
                                          Last post
                                        0
                                        • Categories
                                        • Recent
                                        • Tags
                                        • Popular
                                        • Bookmarks
                                        • Search