mindreframer

mindreframer

Showing Posts 1 to 10

sanswork

sanswork

https://github.com/hexpm/hexpm/issues/1317

I’m following this for updates so I don’t have to just keep refreshing :slight_smile:

sodapopcan

sodapopcan

Wait, is someone manually updating hex.pm’s letsencrypt certificate based off of the email reminders that recently stopped? I was doing this with a client and they emailed me today about this very issue because I kept telling myself every three months “Oh right, I gotta set up a cron for this, ugh… I’ll do it this afternoon…” :sweat_smile:

mindreframer

mindreframer OP

Thanks, did not know this was already a known issue. 4 hours already…

mindreframer

mindreframer OP

thats Claude telling me it’s quite possible to have those certificates renewed like 30 days before they expire… that way there is plenty of time to intervene manually in case of some automated renewal issues.

I’ve been on the other side of having those kinds of things ruining my day, so please don’t take this as an smart-ass reply. We are all human after all.

# Let's Encrypt Certificate Early Renewal Guide

## Overview

Yes, you can absolutely renew a Let's Encrypt certificate well before it expires! This is not only possible but considered best practice for maintaining secure SSL/TLS certificates.

## Key Facts

- Let's Encrypt certificates are valid for **90 days**
- **Recommended renewal time**: 30 days or less remaining
- Early renewal provides a safety buffer in case of renewal issues
- Automatic renewal systems typically trigger at the 30-day mark

## Manual Renewal Commands

### Force Immediate Renewal
```bash
certbot renew --force-renewal

Check Certificate Status

certbot certificates

Test Renewal Process (Dry Run)

certbot renew --dry-run

Automatic Renewal Setup

Cron Job Example

Most systems benefit from automated renewal checks. Here’s a typical cron entry that runs twice daily:

# Add to crontab (crontab -e)
0 12 * * * /usr/bin/certbot renew --quiet

Systemd Timer

Many modern Linux distributions use systemd timers instead of cron:

# Check if certbot timer is active
systemctl status certbot.timer

# Enable automatic renewal
systemctl enable certbot.timer
systemctl start certbot.timer

Best Practices

  1. Set up automatic renewal - Don’t rely on manual renewals
  2. Monitor renewal logs - Check that automatic renewals are working
  3. Use dry-run testing - Verify your renewal process works before you need it
  4. Renew at 30 days remaining - This is the sweet spot for timing
  5. Have monitoring in place - Get alerts if renewals fail

Alternative ACME Clients

If you’re not using Certbot, other popular ACME clients also support early renewal:

  • acme.sh - Lightweight shell script alternative
  • Traefik - Reverse proxy with built-in ACME support
  • Caddy - Web server with automatic HTTPS
  • cert-manager - Kubernetes certificate management

Rate Limits

Let’s Encrypt has rate limits, but they’re generous for normal use:

  • 50 certificates per registered domain per week
  • 5 duplicate certificates per week (same set of hostnames)

The --force-renewal flag will create a duplicate certificate, so use it sparingly.

Troubleshooting

If renewal fails, common issues include:

  • Webserver configuration blocking the challenge
  • Firewall blocking port 80 or 443
  • DNS changes affecting domain validation
  • File permissions on certificate directories

Always test with --dry-run first to catch issues without hitting rate limits.

sodapopcan

sodapopcan

That was the sentiment of my comment. I know I can set up a cron, I know when it can be done (without asking AI), but I just didn’t… partially because in a weird way I enjoy doing it manually (I only have one freelance client as I work work a full time job, if I had more I would have nipped this in the bud long ago). So I was delighting at the idea that maybe (and it probably isn’t even the case) that an owner of hex is doing the same :slight_smile:

mindreframer

mindreframer OP

It’s working now!
Thanks Elixir team!

mindreframer

mindreframer OP

Enjoying the manual renewal… Heh… That’s one special joy, for sure. ))))

sodapopcan

sodapopcan

It’s all about that shh’ing into prod—what is life without it…? :sweat_smile: :upside_down_face:

mindreframer

mindreframer OP

I… guess… Keeps one sharp :slight_smile:

sodapopcan

sodapopcan

Hey, you’re the one who said we’re all human… there is a huge amount of irrationality that comes with that, even among the most rational of us :slight_smile:


Also, I’m still not getting access to hex.pm here (I’m in Canada).

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
ChrisAmelia
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication): toke...
New
dillonoconnor
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New
thiagogsr
** (ArgumentError) expected :max_attempts to be a positive integer, got: {:@, [line: 10, column: 19], [{:max_attempts, [line: 10, column:...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews