Mailcow-dockerized: Acme don麓t get renewed when own certificate is placed

Created on 24 Oct 2018  路  5Comments  路  Source: mailcow/mailcow-dockerized

Describe the bug
If a own certificate is placed for e.g. mail.mailcow.host in data/assets/ssl/cert.pem, acme.sh wont request the certs for the further autodiscover / autoconfig Domains:

Found certificate with issuer other than mailcow snake-oil CA and Let's Encrypt, skipping ACME client...

IMHO this should request, too

How to reproduce Reproduce
Place a cert as described in https://mailcow.github.io/mailcow-dockerized-docs/firststeps-ssl/#use-own-certificates

Expected behavior
It should still request the le cert for the autoconfig / autodiscover Domains.

Logs
Found certificate with issuer other than mailcow snake-oil CA and Let's Encrypt, skipping ACME client...

System

  • Ubuntu 17.10

Most helpful comment

It is very, very, very important that a feature that covers this can be used universally, does not break current configs or migrates them flawless. It would be much easier to just use a reverse proxy for the autodiscover domains, everything else is very likely to break acme-mailcow.

I don't plan to integrate it at the moment.

All 5 comments

How? It can only handle one certificate.

E.g. by using another vhost for the autoX Subdomains

See #461, that's a feature I see for commercial setups. There are workarounds described in this issue and a reason why it has no high priority at the bottom.

I will close it as duplicate. :-)

Hmm - would handle it a little different.

461 could also happen with providing this Feature.

Could change this from bug to feature and lets check if i could provide a PR.
Or should i open a new issue for that

It is very, very, very important that a feature that covers this can be used universally, does not break current configs or migrates them flawless. It would be much easier to just use a reverse proxy for the autodiscover domains, everything else is very likely to break acme-mailcow.

I don't plan to integrate it at the moment.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

phipag picture phipag  路  3Comments

damdinsharav picture damdinsharav  路  3Comments

RogerSik picture RogerSik  路  3Comments

K2rool picture K2rool  路  3Comments

thannaske picture thannaske  路  3Comments