# Let's Encrypt certificate did not automatically renew

**URL:** https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186
**Category:** Support
**Created:** [October 4, 2021, 7:38pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186 "2021-10-04T19:38:00Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [October 4, 2021, 7:38pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/1 "2021-10-04T19:38:01Z")

</div>

Hello,

I’ve done a search on this, but from what I can tell, since I used the default Discouse way to get my Let’s Encrypt certificate, it should renew automatically. But that didn’t happen. (see image below)

After a search on this forum, I installed certbot using ssh, but when I type in “certbot certificates”, it’s not even finding the expired certificate so “certbot renew” does nothing.

Is there something I’m missing? What exactly do I need to do to renew my certificate on my Discourse install?

Please let me know. Thanks!

 ![2021-10-04_12-32-11](https://global.discourse-cdn.com/meta/original/3X/a/b/abe1526c6405e47eecad329e1cc6410b4ff1a592.png)

---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [October 4, 2021, 7:42pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/2 "2021-10-04T19:42:39Z")

</div>

Maybe this is related? [Letsencrypt certificate failure to renew](https://meta.discourse.org/t/letsencrypt-certificate-failure-to-renew/204885)

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [October 4, 2021, 7:46pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/3 "2021-10-04T19:46:16Z")

</div>

Thank you for that. 🙂 It seems like the solution recommended there is to rebuild the app and wait. Well, I did rebuild the app this morning just as a general prophylactic. If that really is the solution, maybe it will fix itself later today?

It’s still showing as expired…

---

<div class="post-metadata">

### Author: ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### Post date: [October 4, 2021, 7:53pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/4 "2021-10-04T19:53:22Z")

</div>

what version of linux are you running?

did you also do an `apt-get update / upgrade ` ?

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [October 4, 2021, 7:56pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/5 "2021-10-04T19:56:25Z")

</div>

It looks like it’s Ubuntu 18.04.4 LTS (GNU/Linux 4.15.0-159-generic x86\_64).

And yes, I did an apt-get update and apt-get upgrade and rebooted my server.

I was hoping some kind of upgrade would fix the issue…

---

<div class="post-metadata">

### Author: ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### Post date: [October 4, 2021, 7:58pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/6 "2021-10-04T19:58:41Z")

</div>

i just checked your cert. its valid

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [October 4, 2021, 8:01pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/7 "2021-10-04T20:01:26Z")

</div>

Thank you, Gavin. It is reporting as Valid in Chrome for me, but when I click on the certificate info itself, it is showing as expired. (see attached screenshot)

Are you showing a new, valid expiration date?

 ![2021-10-04_13-00-02](https://global.discourse-cdn.com/meta/original/3X/8/c/8c7e6e82217cc6c9a352a00e0abd9e10ef02e161.png)  
 ![2021-10-04_13-00-13](https://global.discourse-cdn.com/meta/original/3X/e/e/ee86bd75e777e1007b0adbc43d7926fb21a94fee.png)

---

<div class="post-metadata">

### Author: ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### Post date: [October 4, 2021, 8:04pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/8 "2021-10-04T20:04:19Z")

</div>

it looks all good on my side.

new date and everything

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [October 4, 2021, 8:06pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/9 "2021-10-04T20:06:58Z")

</div>

Ah. Good. It’s still not showing with a valid date in Chrome, even after I deleted my browsing cache, but I just checked in Safari, and I do see a new, valid date.

So, I guess rebuilding the app was the solution, and hopefully Chrome is just a caching issue.

Thank you for checking that out for me. 🙂

---

<div class="post-metadata">

### Author: ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### Post date: [October 4, 2021, 8:08pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/10 "2021-10-04T20:08:06Z")

</div>

no problem. anytime 🙂

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [October 4, 2021, 8:19pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/11 "2021-10-04T20:19:06Z")

</div>

> [@alexwoolfson](#):
>
> So, I guess rebuilding the app was the solution, and hopefully Chrome is just a caching issue.

I believe that is the case. It can be difficult to get `<some browsers>` to report the correct cert, sometimes (and that’s more than I know).

---

<div class="post-metadata">

### Author: ![JimPas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jimpas/32/148179_2.png) [@JimPas](https://meta.discourse.org/u/JimPas)
#### Post date: [October 5, 2021, 12:04am UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/12 "2021-10-05T00:04:00Z")

</div>

> [@alexwoolfson](#):
>
> It’s still not showing with a valid date in Chrome, even after I deleted my browsing cache

I’ve seen a couple of cases where one had to clear the cache and restart Chrome before it showed the valid certificate.

> [@pfaffman](#):
>
> It can be difficult to get `<some browsers>` to report the correct cert, sometimes

Some browsers have a chain of trust cached which includes the old X1 leaf certificate - which LetsEncrypt has ended. They’ll “choke” when they get to that old cert and find it expired. 🤨  
The predicament: Updated browsers are happy with the new shorter chain of trust whereas older browsers still want the longer chain of trust. It’s all about updating everything for more security.

One way of updating your server using acme.sh v3.0.1+ to use the preferred chain of trust is:

[Preferred Chain · acmesh-official/acme.sh Wiki · GitHub](https://github.com/acmesh-official/acme.sh/wiki/Preferred-Chain)

Set the shorter ISRG preferred chain system wide by default with letsencrypt and then renewing all certificates

```plaintext
acme.sh --upgrade
acme.sh --set-default-chain --preferred-chain "ISRG" --server letsencrypt
acme.sh --renewAll --force

```

This is actually one of the very few times that the `--force` flag is appropriate.  
Beware though… older browsers may refuse the shorter chain of trust and will insist on getting the cert. This can also be downloaded as an alternate chain of trust. I believe Lets Encrypt has a link expressly for that purpose. I’ll hop on over there, get that and post it here.

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [October 5, 2021, 6:43pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/13 "2021-10-05T18:43:04Z")

</div>

Roger this, JimPas. Thank you. Even after I cleared the cache in my Chrome and restarted it, I’m still seeing the old certificate. (But in different browsers, I can see that the certificate is renewed.)

Please let me know if you’re able to find that alternate chain of trust link.

Thank you for your help!

---

<div class="post-metadata">

### Author: ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### Post date: [October 5, 2021, 7:43pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/14 "2021-10-05T19:43:48Z")

</div>

have you updated your Chrome Browser ?

type this in your url bar `chrome://settings/help`

---

<div class="post-metadata">

### Author: ![JimPas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jimpas/32/148179_2.png) [@JimPas](https://meta.discourse.org/u/JimPas)
#### Post date: [October 5, 2021, 8:42pm UTC](https://meta.discourse.org/t/lets-encrypt-certificate-did-not-automatically-renew/205186/15 "2021-10-05T20:42:59Z")

</div>

Sorry for the delay - a little bit of an accident last night. Here’s the links to download the X1 & X2 certs and the intermediate leaf cert.  
LE Root CA Certificates (PEM format):

ISRG Root X1  
[https://letsencrypt.org/certs/isrgrootx1.pem](https://letsencrypt.org/certs/isrgrootx1.pem)  
ISRG Root X2  
[https://letsencrypt.org/certs/isrg-root-x2.pem](https://letsencrypt.org/certs/isrg-root-x2.pem)

Intermediate Certificate (PEM format):

Let’s Encrypt R3  
[https://letsencrypt.org/certs/lets-encrypt-r3.pem](https://letsencrypt.org/certs/lets-encrypt-r3.pem)
