If you reuse this article in some tickets, ask customers why it is important to them to rename LE certificates. Post their answers to https://jira.plesk.ru/browse/EXTLETSENC-483 as comments
Applicable to:
- Plesk for Linux
Symptoms
-
Let's Encrypt auto-renew task is not working for Plesk or a domain.
-
Plesk log
/var/log/plesk/panel.logcontains following entries with debug being enabled:CONFIG_TEXT: INFO [extension/letsencrypt] Check if Panel or Mail Server is secured by Let's Encrypt certificate...
INFO [extension/letsencrypt] Panel or Mail Server is not secured by the Let's Encrypt certificate.
Cause
Let's Encrypt extension bug #EXTLETSENC-483 (Cannot auto-renew certificates in Plesk if they were renamed previously) which is planned to be fixed in future product updates.
Let's Encrypt auto-renew feature relies on certificate names and does not recognize certificate names other than Lets Encrypt example.com on domain level and Lets Encrypt certificate on server level..
Resolution
Until a fix became available, as a workaround, renew the certificate manually:
- Log in to Plesk.
- Renew the certificate manually in Tools & Settings > SSL/TLS Certificates > + Let's Encrypt:
- Log in to Plesk.
- Renew this certificate manually from Domains > example.com > SSL/TLS Certificates > Get it free.
Comments
Hi, would it be sufficient to simply rename the certificate back to its original name? When I did this, the error message disappeared.
I would also like to ask what happens when the certificate is manually reissued. Is a completely new certificate created, meaning that the wildcard certificate would have to be manually reassigned to all subdomains, or is the existing certificate simply updated?
Thank you.
Please sign in to leave a comment.