Jump to content
Froxlor Forum


  • Content Count

  • Joined

  • Last visited

Community Reputation

0 Neutral

About peterpan

  • Rank

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. I found the following line in the output: [Sun Sep 15 15:13:43 CEST 2019] Sign failed: "detail":"Error creating new cert :: too many certificates already issued for exact set of domains: xxxxxxx.ca,xxxxxxx.de,xxxxxxx.es,xxxxxxx.fr,xxxxxxx.it,xxxxxxx.net,xxxxxxx.nl,xxxxxxx.us,cron.xxxxxxx.net,webhook.xxxxxxx.net,www.xxxxxxx.ca,www.xxxxxxx.de,www.xxxxxxx.es,www.xxxxxxx.fr,www.xxxxxxx.it,www.xxxxxxx.net,www.xxxxxxx.nl,www.xxxxxxx.us: see https://letsencrypt.org/docs/rate-limits/" As a result, I seem to get a faulty cert from LE, instead of no cert at all. Then, when restarting Apache, it f
  2. It seems to work. When I add a domain as an alias, a new certificate is created. But the certificate is not good: # openssl x509 -in /etc/ssl/froxlor-custom/xxxxxxx.net.crt -text -noout unable to load certificate 140135579193600:error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag:../crypto/asn1/tasn_dec.c:1130: 140135579193600:error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error:../crypto/asn1/tasn_dec.c:290:Type=X509 140135579193600:error:0906700D:PEM routines:PEM_ASN1_read_bio:ASN1 lib:../crypto/pem/pem_oth.c:33: The content of the certificate i
  3. When I run 'git apply' on this, it says: although it says "SELECT" at line 62. I am on the latest version:
  4. Yes, sure, but there are situations where the domain is not available afterwards, such as not-responsive DNS or a domain that doesn't exist anymore. Not always sure that the domain is removed from Froxlor in that case.
  5. 'tasks' outputs nothing about removing the certificate. I can't get my finger behind it, but in some situations the 'renew' switch is used, where it should be 'issue'. In other situations, 'issue' is used correctly. Also interesting: if an error occurs when getting the certificate (e.g. the domain validation fails), there is no retry for the certificate. At the next run, it says "No new certificates or certificates due for renewal found".
  6. I ran the cronjob from the console with '--letsencrypt --force'.
  7. Actually, something did change: I added the new domain as an alias of an existing domain. In the acme.sh command it says '-d new_domain' (correct), so the '--renew' switch is probably not the right choice by your script.
  8. I put an echo on line 298 in froxlor/lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php to see what acme.sh does. When deleting the certificate from the list in Froxlor, it says "Domains not changed" and does nothing. The existing certificate is then copied from /root/.acme.sh to /etc/ssl/froxlor-custom. When adding a domain (as an alias of the existing domain), the command looks like this: ``` /root/.acme.sh/acme.sh --auto-upgrade 0 --server https://acme-v01.api.letsencrypt.org/directory --renew -d existing_domain.net -d new_domain.net --keylength 4096 ``` Since it says '--
  9. This is what I see with the debug switch. Without it, I see no such output.
  10. This is what I see: [information] Adding SAN entry: xxx.yyy [information] Updated Let's Encrypt certificate for xxx.zzz [information] Let's Encrypt certificates have been updated The date of the certificate on disk has changed to the current time, but not its size, and not its content. openssl x509 -in xxx.crt -text -noout does not show the new domains.
  11. This doesn't seem to work. I deleted it from the SSL certificates page, but with the next cronjob, it came back exactly as before, with same domains, same creation date and same expiration date. I even deleted the certificate file from disk in /etc/ssl/froxlor-custom/, but that didn't make any difference as well.
  12. Hi, I have a domain equipped with a certificate from LE. The cert is valid another 2 months. Now I added a domain as an alias of the existing domain, but the certificate isn't updated to have the new domain as its SAN. How do I trigger getting a new and updated certificate? Should I delete the existing one? Thanks for helping out. Peter
  • Create New...