bncert does not automatically renew your certificate - Lightsail docs incorrect

0

The documentation for Lightsail under the How-to, "Enabling HTTPS on your WordPress instance in Amazon Lightsail" specifically says the following:

"However, Certbot does not automatically renew your certificate like the bncert tool."

I used the bncert tool about a year ago, and recently received emails from "Let's Encrypt" saying that the certificate was going to expire. I thought this might be an error, because the documentation above made clear that the bncert tool would automatically renew it. The certificate expired.

If the bncert tool does not automatically renew the certificate, then the above documentation is not merely unclear, it makes an outright false claim.

Does it need to be corrected, or did I miss something?

질문됨 5달 전255회 조회
2개 답변
1
수락된 답변

Hi,

Let's Encrypt certificates are only valid for 90 days. The bncert tool helps setup auto-renewal for the certificate.

Since you setup the certificate and bncert about a year ago and only recently received the expiration email - it sounds like something has changed or been broken in the setup since (i.e. renewal was working correctly earlier)

Does the email contain some information about any renewal failures ? Else your actual instance must have logs from the bitnami tool on certificate renewal attempts and what went wrong.

You may also find some helpful information here - https://repost.aws/knowledge-center/lightsail-bitnami-renew-ssl-certificate

profile pictureAWS
전문가
AWS-SUM
답변함 5달 전
profile picture
전문가
검토됨 5달 전
  • Thank you for your reply.

    With regard to these details, the email only says that the certificate will expire in X days, and to please be sure to renew it before then. Based upon the two answers here, it may be that I had the machine shut down during the period when the certificate would have otherwise been auto-renewed by bncert (prior to this continuing 90-day expiration window).

    I didn't fully understand that this was the process.

    Do you happen to know of bncert has a quick command for running an ad-hoc renewal?

  • The same command used to setup bncert the first time can be re-run again and it should help set it back up.

    Please refer Step 5: Enable HTTPS on your WordPress instance from https://lightsail.aws.amazon.com/ls/docs/en_us/articles/amazon-lightsail-enabling-https-on-wordpress and follow the prompts thereafter.

  • Thanks, @AWS-SUM!

1

Hello.

Looking at the document below, it seems that certificates are updated every 80 days.
In other words, the fact that a certificate issued one year ago was usable until recently means that it was possible to renew it until now.
Therefore, for some reason, the renewal was not successful and the certificate has recently expired.
https://lightsail.aws.amazon.com/ls/docs/en_us/articles/amazon-lightsail-enabling-https-on-wordpress?trk=d7920dcb-23ef-4a3f-9619-088dfdc45d2e&sc_channel=ta

The bncert tool will perform an automatic renewal of your certificate every 80 days before it expires. Repeat the above steps if you wish to use additional domains and subdomains with your instance, and you want to enable HTTPS for those domains.

I thought that there would be no problem if I executed the following command and updated it again.

sudo /opt/bitnami/bncert-tool
profile picture
전문가
답변함 5달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인