手动执行certbot renew后仍显示ERR_CERT_DATE_INVALID及自动续期异常咨询
Troubleshooting Certbot Renewal Issues: Manual Renewal Not Reflecting & Cron Job Failure
Let's tackle your two issues one by one to get your certificates working properly again.
1. Why the website still shows ERR_CERT_DATE_INVALID after manual certbot renew?
First, we need to confirm if the renewal actually succeeded, then rule out common post-renewal hiccups:
- Verify the certificate's actual status: Run
certbot certificatesin your terminal. This will list all managed certificates with their expiration dates. If the date still shows the old, expired one, your manual renewal failed—check the detailed logs at/var/log/letsencrypt/letsencrypt.logto find errors (like domain validation failures or permission issues). - Reload/restart your web server: Certbot doesn't always automatically trigger a server reload to pick up the new certificate. For Nginx, run
sudo systemctl reload nginx; for Apache, usesudo systemctl restart apache2. To make this automatic in future renewals, add a deploy hook:certbot renew --deploy-hook "systemctl reload nginx". - Clear browser cache: Browsers often cache old certificate data. Try accessing your site in incognito/private mode, or clear your browser's SSL cache to rule this out.
- Check web server config paths: Ensure your server (Nginx/Apache) is pointing to the correct live certificate files from Certbot. For example, Nginx should have:
If it's pointing to old, static files instead of these symlinks, the server won't pick up renewed certificates.ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem;
2. Why isn't the cron job 15 3 * * * certbot renew --quiet running automatically?
Cron issues usually boil down to environment, permissions, or configuration errors:
- Check cron logs: Look for entries related to Certbot in your system's cron logs. On Ubuntu/Debian, this is
/var/log/syslog; on RHEL/CentOS, it's/var/log/cron. Search forcertbotto see if the job ran, and if there are any error messages (e.g., "command not found" means Certbot's path isn't in cron's PATH). - Use the full path to Certbot: Cron uses a minimal PATH environment variable, so
certbotmight not be found. Replacecertbotwith its absolute path (find it withwhich certbot—usually/usr/bin/certbot). Your cron line should become:15 3 * * * /usr/bin/certbot renew --quiet - Test the cron command manually: Run
/usr/bin/certbot renew --quietas the user who owns the crontab (usually root—usesudoif needed). If this throws errors, fix those first (e.g., domain validation issues) before worrying about cron. - Check if renewal is needed yet: Certbot only renews certificates when they're within 30 days of expiration. Use
certbot renew --dry-runto simulate the renewal process—this will tell you if your configuration is valid and if a renewal would trigger when the time comes. - Confirm the cron job exists: Run
sudo crontab -l(if using root's crontab, which is recommended for Certbot) to make sure the job is listed and has no typos (e.g., extra spaces, misspelled--quiet).
内容的提问来源于stack exchange,提问作者Mathieu Ferre
相关产品推荐
相关产品推荐

