Bug ? - lestencrypt repeats renewal every 5 mins

6 posts / 0 new
Last post
#1 Tue, 06/14/2016 - 12:45
SteveR

Bug ? - lestencrypt repeats renewal every 5 mins

My letsencrypt cert for one of my sites was set to auto renew in virtualmin. It apparently renewed successfully and has then been repeated the request every 5 mins since, resulting in:
multiple Let's encrypt cert renewal failed messages every 5 mins, with the error:
There were too many requests of a given type...
No doubt also getting me a bad reputation with lestencrypt.
In addition when I turned off the autorenewal, it still kept going

This needs fixing, at least you should limit the number of repeat attempts.

Tue, 06/14/2016 - 22:16
coderinthebox

Check if you have a cron job that was running every 5 mins to renew the certificate. I notice that some people add cronjobs for Lets Encrypt renewal

Visit me at coderinthebox.com

Sat, 06/18/2016 - 12:18
unborn
unborn's picture

I dont know what distro you are using but this is defo not happening on my servers.

Configuring/troubleshooting Debian servers is always great fun

Sun, 06/19/2016 - 05:57
ErikNL

Same problem here. There is no configured cron polling letsencrypt at my server. Somewhere else I've read Virtualmin will have this issue fixed in the next update where a certificate will only be polled once every 24 hours of something like that...waiting for that update since letsencrypt can't be used at my server with the same problem the creator of this thread has.

Tue, 06/28/2016 - 12:00 (Reply to #4)
unborn
unborn's picture

@ErikNL this topic was created by someone else, but towards your issue - in lets encrypt tab on selected domain, you should choose 2 months instead of 24 hours. First you can request 5 cerst per 7 days for same *domain.com. For second, certs are valid for 90 days so if you apply for cert and it is issued correctly in future - if ssl is not issued correctly by lets encrypt you will still have one month to troubleshoot your own srv (with valid cert on it) which is more then enough. Requesting new certs every 24 hours would end up in problem.

Configuring/troubleshooting Debian servers is always great fun

Tue, 06/28/2016 - 12:58
andreychek

Howdy,

Jamie is adding in a fix for this issue in the next Virtualmin version. There's a problem that can occur where if Let's Encrypt blocks or denies the certificate during the renewal process, it can get caught in a loop.

The next Virtualmin version will prevent that from occurring.

In the meantime, you may need to set them to not renew automatically. But I'll talk to Jamie about pushing that new version out soon.

-Eric

Topic locked