Fix Let's Encrypt issuer detection with OpenSSL 3.x

openssl x509 -issuer changed its default output format between
OpenSSL 1.1.1 and 3.x: the old format has no spaces around '='
(O=Let's Encrypt), the new one does (O = Let's Encrypt). The
renew.sh issuer check used a literal grep -q "O=Let's Encrypt", so
on OpenSSL 3.x (e.g. current ESXi releases) it never matches and
the script treats every existing Let's Encrypt cert as untrusted,
requesting a brand new certificate on every scheduled run instead
of only when it's actually close to expiry. This risks hitting
Let's Encrypt's rate limits.

Match the issuer with optional whitespace around '=' so it works
with both OpenSSL output formats.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
andyandClaude Sonnet 5 authored and Johannes Feichtner committed 2026-09-20 13:11:50 +02:00
1 parent 27598a9070
commit a4fc32b6ce
1 file changed
+1 -1
+1 -1
View File
@@ -50,7 +50,7 @@ if [ -e "$VMWARE_CRT" ]; then
if [ "$SAN" != "$DOMAIN" ] ; then
log "Existing cert issued for ${SAN} but current domain name is ${DOMAIN}. Requesting a new one!"
# If the cert is issued by Let's Encrypt, check its expiration date, otherwise request a new one
elif openssl x509 -in "$VMWARE_CRT" -issuer -noout | grep -q "O=Let's Encrypt"; then
elif openssl x509 -in "$VMWARE_CRT" -issuer -noout | grep -qE "O ?= ?Let's Encrypt"; then
CERT_VALID=$(openssl x509 -enddate -noout -in "$VMWARE_CRT" | cut -d= -f2-)
log "Existing Let's Encrypt cert valid until: ${CERT_VALID}"
if openssl x509 -checkend $((RENEW_DAYS * 86400)) -noout -in "$VMWARE_CRT"; then