LetsEncrypt auto-renew is using sub server domain instead of wildcard

SYSTEM INFORMATION
OS type and version Ubuntu 22.04/Debian 11
Webmin version 2.101
Virtualmin version 7.8.2
Related packages Certbot? certbot.timer disabled/masked via systemctl

Thanks in advance for any assistance; although this certainly isn’t urgent it is aggravating.

I’m having an issue during auto-renewal of SSL certs; I have it set to request wildcard certificates. However, when auto-renewal happens it ends up using a subserver/domain for it. SSL sharing is enabled. I can manually request/renew wildcard via Let’sEncrypt tab of SSL management, although sometimes I have to do it a second time (I assume due to delay in DNS propagation, I have increased the timeout which doesn’t seem to help).

I get an email showing that wildcard auto-renewal failed (same DNS-based validation failure I get when I do it manually and have to do a second run for it to “take”) and then a little later, another email showing renewal of one of the subservers (rhox.org, *.rhox.org failure, followed by mta-sts.rhox.org success).

How can I go about verifying/troubleshooting configuration settings/conflicts? Do I need certbot, or CAN/should I remove/purge it outright and allow virtualmin to use it’s built-in scripts (unless that isn’t a thing anymore, I read mention of it in other posts a while back). Will disabling/enabling SSL website for each subserver force a reset of the SSL sharing which seems to have glitched?

Hello,

Thanks for the heads up! I think, this is exactly the issue we recently fixed just recently. Please have a look at this thread:

This makes me feel somewhat better - the issue has happened in the past and I thought I had fixed it by manually setting some of the flags/keys in the domain files in /etc/webmin/virtual-server/domains but then it happened again :stuck_out_tongue:

That thread suggests it has been fixed but this occurred just yesterday. Is it fixed in the code but not pushed to/via a release just yet? I would imagine if so my next renewal will hopefully be a tad smoother in a couple months, which seem to come faster and faster don’t they?

Thank you for your attention :slight_smile:

Yes, correct.

1 Like

Sir it’s been too long and still new webmin is not coming in virtualmin repo. Is it going to come with new virtualmin version? Can you give any estimates.
Thankyou

We cannot provide any ETA.

1 Like

This topic was automatically closed 8 days after the last reply. New replies are no longer allowed.