I have about 20 domains using free Let's Encrypt certificates that auto-renew.
Sometimes they renew just fine.
Other times, the domain will renew, but the webmail and/or www subdomains will not. The error shown says something about connection, possibly firewall.
The thing is - it's random! And when I manually reissue the certificate, it usually renews the domain, and the www and webmail subdomains just fine. Once or twice I've had to reissue 2 or 3 times because of the same connection/firewall error.
I DO have a some small Amazon ip address ranges blocked in my firewall - but would this explain why the domain renews but the www and/or webmail doesn't renew at the same time? Could Let's Encrypt be using different IPs to verify the domain and the www subdomain and the webmail subdomain? If I could be certain this is the issue, I guess I could remove those blocks from my firewall (but I would hate to - these ranges were added due to excessive abuse on my server!)
If I cannot resolve this another way, I'd be happy to just have some sort of method to check all the subdomains (the emails are NOT helpful.) I found a PowerShell script to check SSL expiration dates, but despite me entering subdomain urls in the script, it appears to be only checking the primary domain, which doesn't help me.
The only tool I've found in Plesk for checking SSL expiration dates is Advisor, and it just shows the expiration of the primary domain, with no clue that the www or webmail is not secured.
Any suggestions for a fix, or for a tool that will check the www and webmail subdomains?
Sometimes they renew just fine.
Other times, the domain will renew, but the webmail and/or www subdomains will not. The error shown says something about connection, possibly firewall.
The thing is - it's random! And when I manually reissue the certificate, it usually renews the domain, and the www and webmail subdomains just fine. Once or twice I've had to reissue 2 or 3 times because of the same connection/firewall error.
I DO have a some small Amazon ip address ranges blocked in my firewall - but would this explain why the domain renews but the www and/or webmail doesn't renew at the same time? Could Let's Encrypt be using different IPs to verify the domain and the www subdomain and the webmail subdomain? If I could be certain this is the issue, I guess I could remove those blocks from my firewall (but I would hate to - these ranges were added due to excessive abuse on my server!)
If I cannot resolve this another way, I'd be happy to just have some sort of method to check all the subdomains (the emails are NOT helpful.) I found a PowerShell script to check SSL expiration dates, but despite me entering subdomain urls in the script, it appears to be only checking the primary domain, which doesn't help me.
The only tool I've found in Plesk for checking SSL expiration dates is Advisor, and it just shows the expiration of the primary domain, with no clue that the www or webmail is not secured.
Any suggestions for a fix, or for a tool that will check the www and webmail subdomains?