Mailcow-dockerized: LetsEncrypt revoking certs today - Cannot force SSL renewal

Created on 3 Mar 2020  路  5Comments  路  Source: mailcow/mailcow-dockerized

Prior to placing the issue, please check following: (fill out each checkbox with a X once done)

  • [ x] I understand, that not following below instructions might result in immediate closing and deletion of my issue.
  • [x ] I have understood that answers are voluntary and community-driven, and not commercial support.
  • [x ] I have verified that my issue has not been already answered in the past. I also checked previous issues.

Description of the bug:

As per https://community.letsencrypt.org/t/revoking-certain-certificates-on-march-4/114864 - LetsEncrypt is revoking certain certs today. I have attempted to force renewal via the steps at https://mailcow.github.io/mailcow-dockerized-docs/firststeps-ssl/ to no avail.

Docker container logs of affected containers:

acme-mailcow_1 | Wed Mar 4 02:31:24 AEDT 2020 - Certificates were successfully validated, no changes or renewals required, sleeping for another day.

Reproduction of said bug:

Have a cert that is being revoked by LetsEncrypt according to https://community.letsencrypt.org/t/revoking-certain-certificates-on-march-4/114864 and try to force renewal

System information:

N/A

  • Output of git diff origin/master, any other changes to the code? If so, please post them.
  • All third-party firewalls and custom iptables rules are unsupported. Please check the Docker docs about how to use Docker with your own ruleset. Nevertheless, iptabels output can help us to help you: iptables -L -vn, ip6tables -L -vn, iptables -L -vn -t nat and ip6tables -L -vn -t nat.
  • DNS problems? Please run docker exec -it $(docker ps -qf name=acme-mailcow) dig +short stackoverflow.com @172.22.1.254 (set the IP accordingly, if you changed the internal mailcow network) and post the output.

Most helpful comment

Oh, sorry, misread it. You probably didn't update. Run ./update.sh and try again. It will renew the certificate with acme-mailcow version 1.68.

All 5 comments

Hi,

check https://mailcow.email/ :)

Update your cow and check https://mailcow.github.io/mailcow-dockerized-docs/firststeps-ssl/#force-renewal

Andr茅

Oh, sorry, misread it. You probably didn't update. Run ./update.sh and try again. It will renew the certificate with acme-mailcow version 1.68.

Thanks for the prompt response and great work! Didn't think to update

(: You are welcome.
For those with a reverse proxy: Do not forget to reload your RP.

Thanks

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Adorfer picture Adorfer  路  3Comments

RogerSik picture RogerSik  路  3Comments

CrAazZyMaN21 picture CrAazZyMaN21  路  3Comments

constin picture constin  路  3Comments

mritzmann picture mritzmann  路  3Comments