Lets encrypt expiry notice to one client for all domains

Discussion in 'ISPConfig 3 Priority Support' started by SpeedyB, Apr 2, 2017.

  1. SpeedyB

    SpeedyB Member HowtoForge Supporter

    Hello,

    I enabled Lets encrypt a little while back. Now is one of my clients getting renewal notices for all domains of the server and not me or the domain owner?

    How can I fix this that he doesn't get all these emails? I don't know if he is the only one who gets them, but only he reported it..

    Regards,
    Bas
     
  2. till

    till Super Moderator Staff Member ISPConfig Developer

    Never seen that yet. he get's notices by email from LE or from ISPConfig?
     
  3. SpeedyB

    SpeedyB Member HowtoForge Supporter

    The mail is send from LE to a mailadres which is not available in the client list.
    When registering the certificate what mailadres is used?
     
  4. till

    till Super Moderator Staff Member ISPConfig Developer

  5. SpeedyB

    SpeedyB Member HowtoForge Supporter

    it appears to be the postmaster adres for the first domain which was added to LE.
     
  6. till

    till Super Moderator Staff Member ISPConfig Developer

    The domain is the domain of the current website where this SSL cert is issued, ispconfig does not even know which the first domain is, and ispconfig passes it via --email option to LE. Maybe LE mixes something up when a server contains more than one site.
     
  7. till

    till Super Moderator Staff Member ISPConfig Developer

    Did you looked into the LE config files in /etc/letsencrypt, most likely you can see there which email address is used.
     
  8. SpeedyB

    SpeedyB Member HowtoForge Supporter

    There is only 1 accounts file with the postmaster domain for the first domain which was added to LE. It seems this account is used on this server.
     
  9. till

    till Super Moderator Staff Member ISPConfig Developer

    Ok, so LE seems to ignore the --email option then when it is used for the second domain. In this case we will have to use the server owners email address in that place I guess.
     
  10. sjau

    sjau Local Meanie Moderator

  11. till

    till Super Moderator Staff Member ISPConfig Developer

    According to the certbot docs, there is a short form -m and a long form --email:

     
  12. sjau

    sjau Local Meanie Moderator

    yeah, I see... that's further down... but why have it twice... damn, thought I found the issue :)
     
  13. till

    till Super Moderator Staff Member ISPConfig Developer

    Nevertheless, thank you for looking into the issue :)
     
  14. SpeedyB

    SpeedyB Member HowtoForge Supporter

    If I change the mailadres in the account file or will that break the file?
     
  15. till

    till Super Moderator Staff Member ISPConfig Developer

    I don't know, you will have to try it.
     

Share This Page