Let's Encrypt Certificate expired

Discussion in 'ISPConfig 3 Priority Support' started by kommid, Jan 19, 2024.

  1. kommid

    kommid Member HowtoForge Supporter

    Hi, on one of my ISPConfig 3.2 Servers, mail clients complain about expired SSL-certificates. The Let's encrypt certificate was renewed today, and it worked out fine for ISPConfig itself but it seems, the mailsererver did not get the new certificate. Any Idea how to fix this?
     
  2. kommid

    kommid Member HowtoForge Supporter

    Never mind. Restarting the services did the job....
     
    Th0m likes this.
  3. Th0m

    Th0m ISPConfig Developer Staff Member ISPConfig Developer

    Maybe you have missed adding a automatic trigger to restart email services when the cert is changed?
     
  4. kommid

    kommid Member HowtoForge Supporter

    How does this trigger look? I set up the server, using one of the HowTos here for Debian stretch, back in 2017 and updated it to buster last year...
     
  5. Taleman

    Taleman Well-Known Member HowtoForge Supporter

    I believe this article should no longer be used, but this is the way it was set up previously:
    https://www.howtoforge.com/tutorial...ote-this-shouldnt-exist-together-with-courier
    ISPConfig 3.2 should know how to restart services when certificate is renewed, I think it uses systemd to detect changes in certificate files. Have you tried ispconfig_update.sh --force and let it reconfigure services?
    Try to find whether you server uses certbot or acme.sh (the common issues script shows this), then figure out why services do not restart when certificate renews.
     
  6. till

    till Super Moderator Staff Member ISPConfig Developer

Share This Page