If you reuse this article in some tickets, ask customers why it is important to them to rename LE certificates. Post their answers to https://jira.plesk.ru/browse/EXTLETSENC-483 as comments
Applicable to:
- Plesk for Linux
Symptoms
-
Let's Encrypt auto-renew task is not working for Plesk or a domain.
-
Plesk log
/var/log/plesk/panel.logcontains following entries with debug being enabled:CONFIG_TEXT: INFO [extension/letsencrypt] Check if Panel or Mail Server is secured by Let's Encrypt certificate...
INFO [extension/letsencrypt] Panel or Mail Server is not secured by the Let's Encrypt certificate.
Cause
Let's Encrypt extension bug #EXTLETSENC-483 (Cannot auto-renew certificates in Plesk if they were renamed previously) which is planned to be fixed in future product updates.
Let's Encrypt auto-renew feature relies on certificate names and does not recognize certificate names other than Lets Encrypt example.com on domain level and Lets Encrypt certificate on server level..
Resolution
Until a fix became available, as a workaround, renew the certificate manually:
- Log in to Plesk.
- Renew the certificate manually in Tools & Settings > SSL/TLS Certificates > + Let's Encrypt:
- Log in to Plesk.
- Renew this certificate manually from Domains > example.com > SSL/TLS Certificates > Get it free.
Comments
Hi, would it be sufficient to simply rename the certificate back to its original name? When I did this, the error message disappeared.
I would also like to ask what happens when the certificate is manually reissued. Is a completely new certificate created, meaning that the wildcard certificate would have to be manually reassigned to all subdomains, or is the existing certificate simply updated?
Thank you.
I can confirm that if you rename the certificate back, it will automatically renew. My certificate just renewed automatically.
Please sign in to leave a comment.