Commit Graph
4 Commits
Author SHA1 Message Date
andyandClaude Sonnet 5 a4fc32b6ce Fix Let's Encrypt issuer detection with OpenSSL 3.x
openssl x509 -issuer changed its default output format between
OpenSSL 1.1.1 and 3.x: the old format has no spaces around '='
(O=Let's Encrypt), the new one does (O = Let's Encrypt). The
renew.sh issuer check used a literal grep -q "O=Let's Encrypt", so
on OpenSSL 3.x (e.g. current ESXi releases) it never matches and
the script treats every existing Let's Encrypt cert as untrusted,
requesting a brand new certificate on every scheduled run instead
of only when it's actually close to expiry. This risks hitting
Let's Encrypt's rate limits.

Match the issuer with optional whitespace around '=' so it works
with both OpenSSL output formats.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-20 13:11:50 +02:00
Johannes Feichtner 9da2a81a7a Read FQDN from hostname command
The previous command stopped working with ESXi 8
2022-12-03 23:56:35 +01:00
Johannes Feichtner a58778311d Keep existing cert while it is still valid
Letsencrypt has some hiccups sometimes during renewals. Instead of instantly replacing a still valid cert with a self-signed, it should be kept, while it hasn't expired
2022-12-03 23:53:11 +01:00
Johannes Feichtner cbe7fd719f Initial commit 2022-06-19 21:31:48 +02:00