The SSL cert that expired on a Sunday
Sunday morning. Coffee in hand. Browser says: Your connection is not private. Cert expired 3 hours ago. Let's Encrypt auto-renewal failed because certbot was configured for the wrong domain variant. 15 minutes of panic, one certbot --force-renewal, and a nginx reload later we were back.
💡 What You Will Learn
Sunday morning. Coffee in hand. Browser says: Your connection is not private. Cert expired 3 hours ago. Let's Encrypt auto-renewal failed because certbot was configured for the wrong domain variant. 1
Sunday's Expired SSL Certificate
Woke up Sunday morning to find the site down. SSL certificate expired. Red warning page.
Manual renewal succeeded, but nginx didn't load the new certificate. Took a while to figure out โ I'd manually edited the nginx config before, pointing it to the old certificate path.
Fix: update the symlink to point to the new certificate, reload nginx.
The whole process took 15 minutes. But that red warning page โ the moment I saw it, my heart rate definitely spiked.
Lesson: SSL monitoring should alert 7 days in advance. Expiring on a Sunday is bound to happen.
Related Posts
Written by our editorial team; tools listed here are tested or verified against public sources. Links point to official sites or GitHub repos for reference only โ no paid placements.
