From a4fc32b6ceb9f30ce207fb08c7b58d8779cf4619 Mon Sep 17 00:00:00 2001 From: andy Date: Fri, 18 Sep 2026 22:38:17 +0000 Subject: [PATCH] Fix Let's Encrypt issuer detection with OpenSSL 3.x openssl x509 -issuer changed its default output format between OpenSSL 1.1.1 and 3.x: the old format has no spaces around '=' (O=Let's Encrypt), the new one does (O = Let's Encrypt). The renew.sh issuer check used a literal grep -q "O=Let's Encrypt", so on OpenSSL 3.x (e.g. current ESXi releases) it never matches and the script treats every existing Let's Encrypt cert as untrusted, requesting a brand new certificate on every scheduled run instead of only when it's actually close to expiry. This risks hitting Let's Encrypt's rate limits. Match the issuer with optional whitespace around '=' so it works with both OpenSSL output formats. Co-Authored-By: Claude Sonnet 5 --- renew.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/renew.sh b/renew.sh index 14f4c29..33ddcfe 100644 --- a/renew.sh +++ b/renew.sh @@ -50,7 +50,7 @@ if [ -e "$VMWARE_CRT" ]; then if [ "$SAN" != "$DOMAIN" ] ; then log "Existing cert issued for ${SAN} but current domain name is ${DOMAIN}. Requesting a new one!" # If the cert is issued by Let's Encrypt, check its expiration date, otherwise request a new one - elif openssl x509 -in "$VMWARE_CRT" -issuer -noout | grep -q "O=Let's Encrypt"; then + elif openssl x509 -in "$VMWARE_CRT" -issuer -noout | grep -qE "O ?= ?Let's Encrypt"; then CERT_VALID=$(openssl x509 -enddate -noout -in "$VMWARE_CRT" | cut -d= -f2-) log "Existing Let's Encrypt cert valid until: ${CERT_VALID}" if openssl x509 -checkend $((RENEW_DAYS * 86400)) -noout -in "$VMWARE_CRT"; then