certbot.txt (2053B)
1 =============================================================================== 2 Certbot / SSL Certificates 3 =============================================================================== 4 5 1. Check what certificate your origin is actually presenting 6 7 # From outside the container, test the origin directly (bypass Cloudflare): 8 9 openssl s_client -connect example.com:443 -servername server.com </dev/null 2>/dev/null | openssl x509 -noout -dates -subject 10 11 # Or if your origin IP is different from what DNS resolves to: 12 13 openssl s_client -connect <your-origin-ip>:443 -servername server.com </dev/null 2>/dev/null | openssl x509 -noout -dates -subject 14 15 16 2. Verify your web server config points to the right paths 17 18 # For nginx 19 grep -r "ssl_certificate" /etc/nginx/conf.d/ /etc/nginx/sites-enabled/ 20 21 # For Apache 22 grep -r "SSLCertificate" /etc/apache2/sites-enabled/ 23 24 25 3. Check if the certificate files exist and are readable 26 27 # Inside the certbot container 28 ls -la /etc/letsencrypt/live/example.com/ 29 30 # Permissions should look roughly like: 31 # -rw-r--r-- on the .pem files 32 33 34 4. Reload your web server 35 36 # Nginx 37 docker exec <your-nginx-container> nginx -s reload 38 39 # Apache 40 docker exec <your-apache-container> apachectl reload 41 42 43 5. The most likely culprit: certbot hasn't actually renewed 44 45 Try a forced renewal to test the full cycle: 46 47 docker exec -it certbot-manager certbot renew --force-renewal 48 # Then reload your web server 49 50 =============================================================================== 51 Auto-renewal: 52 53 In order to have auto-renewal running in the background, you certbot-manager 54 docker container has to be running in daemon mode, then it will continuously 55 check for certfificate validity every 12 hours: 56 57 docker compose -f compose-renew.yml up --build -d 58 59 60 and then dry run renewal to check which domain is due for renewal: 61 62 docker exec -it certbot-manager certbot renew --dry-run 63 64 65 Make sure the manager is actually running persistently: 66 67 docker compose -f compose-renew.yml up -d 68 docker compose -f compose-renew.yml logs -f certbot-manager