#3606 accepted infra

Crontab Let's Encrypt certificates.

Reported by: Amar Takhar Owned by: Amar Takhar
Priority: highest Milestone: Indefinite
Component: admin Version:
Severity: normal Keywords: funded project-1
Cc: Blocked By: #4784
Blocking:

Description

Doing this manually over as many certificates we have is causing too many issues.

This needs to be crontabed for every 30 days safely.

Change History (10)

comment:1 Changed on 11/13/18 at 16:30:30 by Amar Takhar

I had already done most of the work for this. All that's left is:

  • A non-annoying crontab so the sysadmin list doesn't get blasted.
  • A monthly check to ensure the certificates have renewed.
  • Restart Apache and Postfix after renewal.

comment:2 Changed on 12/05/18 at 03:39:15 by Amar Takhar

Closer to getting this done I need to figure out how to best handle getting the certificate for our MTA.

comment:3 Changed on 02/13/19 at 20:33:23 by Amar Takhar

Milestone: 5.15.2

Moving this to 5.2 I just updated this a few days ago.

comment:4 Changed on 01/29/20 at 23:17:21 by Chris Johns

Is this done and can it be closed?

comment:5 Changed on 01/29/20 at 23:49:07 by Amar Takhar

This was nearly done I will look at it again and try to complete it and close this ticket thank you for the reminder.

comment:6 Changed on 01/30/20 at 00:00:55 by Chris Johns

Thanks. I got a reminder we are in the final 10 day window for them to expire.

comment:7 Changed on 08/17/22 at 06:06:39 by Chris Johns

Milestone: 5.2Indefinite

comment:8 Changed on 01/19/23 at 16:32:57 by Amar Takhar

Blocked By: 4784 added
Keywords: need-funding added; www removed

comment:9 Changed on 01/25/23 at 21:04:39 by Amar Takhar

Keywords: funded project-1 added; need-funding removed
Status: assignedaccepted

This project has been funded by an anonymous donor, thank you!

comment:10 Changed on 01/26/23 at 19:42:41 by Amar Takhar

certbot has built-in support to handle this very nicely now on a global basis. We'll be using that and crontabing it to do updates on our certificates every 7 days.

The MTA will also be included on this as well as the FTP site.

Note: See TracTickets for help on using tickets.