From owner-freebsd-questions@freebsd.org Thu Sep 10 22:21:41 2020 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 8CA443E5ED7 for ; Thu, 10 Sep 2020 22:21:41 +0000 (UTC) (envelope-from lysfjord.daniel@smokepit.net) Received: from smtp-out.smokepit.net (smtp-out.smokepit.net [18.200.56.156]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "smtp-out.smokepit.net", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4BnYJh1ySrz4k6C for ; Thu, 10 Sep 2020 22:21:39 +0000 (UTC) (envelope-from lysfjord.daniel@smokepit.net) Received: from cm-84.215.33.184.getinternet.no ([84.215.33.184] helo=smokepit.net) by smtp-out.smokepit.net with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kGUwf-0000Sp-DU for freebsd-questions@freebsd.org; Thu, 10 Sep 2020 22:21:33 +0000 Received: from http01.lan.smokepit.net ([10.0.3.111] helo=webmail.smokepit.net) by smokepit.net with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94 (FreeBSD)) (envelope-from ) id 1kGUwc-000MVb-A6 for freebsd-questions@freebsd.org; Fri, 11 Sep 2020 00:21:31 +0200 MIME-Version: 1.0 Date: Thu, 10 Sep 2020 22:21:30 +0000 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Mailer: RainLoop/1.14.0 From: "Daniel Lysfjord" Message-ID: Subject: Re: py37-certbot question To: freebsd-questions@freebsd.org In-Reply-To: References: X-Originating-IP: 10.0.0.200 X-Spam-Report: Action: no action Symbol: ARC_NA(0.00) Symbol: RCVD_VIA_SMTP_AUTH(0.00) Symbol: HAS_XOIP(0.00) Symbol: FROM_HAS_DN(0.00) Symbol: TO_MATCH_ENVRCPT_ALL(0.00) Symbol: BAYES_HAM(-2.62) Symbol: MIME_GOOD(-0.10) Symbol: TO_DN_NONE(0.00) Symbol: RCPT_COUNT_ONE(0.00) Symbol: RCVD_COUNT_ONE(0.00) Symbol: FROM_EQ_ENVFROM(0.00) Symbol: MIME_TRACE(0.00) Symbol: RCVD_TLS_ALL(0.00) Symbol: MID_RHS_MATCH_FROM(0.00) Message-ID: e427f06d794c8bb1fa66e416e09da196@smokepit.net X-Rspamd-Queue-Id: 4BnYJh1ySrz4k6C X-Spamd-Bar: -- X-Spamd-Result: default: False [-2.93 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; R_DKIM_ALLOW(-0.20)[smokepit.net:s=loke]; HAS_XOIP(0.00)[]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; MIME_GOOD(-0.10)[text/plain]; TO_DN_NONE(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.002]; RCPT_COUNT_ONE(0.00)[1]; RCVD_COUNT_THREE(0.00)[3]; NEURAL_HAM_MEDIUM(-0.66)[-0.662]; R_SPF_ALLOW(-0.20)[+ip4:18.200.56.156]; DKIM_TRACE(0.00)[smokepit.net:+]; DMARC_POLICY_ALLOW(-0.50)[smokepit.net,reject]; NEURAL_HAM_SHORT(-0.26)[-0.264]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:16509, ipnet:18.200.0.0/16, country:US]; RCVD_TLS_ALL(0.00)[]; MAILMAN_DEST(0.00)[freebsd-questions]; RECEIVED_SPAMHAUS_PBL(0.00)[84.215.33.184:received] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.33 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 10 Sep 2020 22:21:41 -0000 "Valeri Galtsev" skrev 10. september 2020 kl.= 23:48:=0A=0A> Dear Experts,=0A> =0A> I hope, someone knows details of py= thon3 based certbot. Namely, if run with "update" command, it=0A> updated= certificates that will expire "soon". How soon, it doesn't say in man pa= ge, just soon. Does=0A> someone know how close to expiration cert should = be to be considered by the script for renewal.=0A=0Ahttps://certbot.eff.o= rg/docs/using.html#renewing-certificates=0ATells me 30 days:)=0A=0A=0A> = =0A> I use certbot since its python 2 version - for quite some time actua= lly to renew LetsEncrypt=0A> certificates. With python2 version in the pa= st I run cron job daily and I was restarting apache=0A> from that same sc= ript if certificate was updated. With python3 version when I switched to = it I=0A> followed somebody's HOWTO, and just added to /etc/periodic.conf:= =0A> =0A> weekly_certbot_enable=3D"YES"=0A> weekly_certbot_service=3D"apa= che24"=0A> =0A> And was living happily ever since. However, one of the ma= chines is about 4 days before expiration,=0A> Letsencrypt sent me notific= ation: update cert. I checked, and crond is runnning, /etc/periodic.conf= =0A> is as expected, and now, 4 days before expiration script (with --dry= run flag) indeed goes about=0A> renewing the cert. There is one weekly c= ron jobs set that will happen before actual expiration of=0A> my certs, s= o I somehow think all is OK and my cert will be renewed.=0A> =0A> But I a= m just curios how many days before expiration certbot does renew certific= ate that will=0A> expire "soon".=0A> =0A> Or should I probably switch it = over to daily cron job?=0A> =0A> As every lazy sysadmin, I do prefer to s= et things up so they definitely work without my attention.=0A> And I do n= ot want to be reminded to do something it it will still happen on its own= . So, switch to=0A> daily cron job?=0A> =0A> Thanks.=0A> Valeri=0A> =0A> = -- ++++++++++++++++++++++++++++++++++++++++=0A> Valeri Galtsev=0A> Sr Sys= tem Administrator=0A> Department of Astronomy and Astrophysics=0A> Kavli = Institute for Cosmological Physics=0A> University of Chicago=0A> Phone: 7= 73-702-4247=0A> ++++++++++++++++++++++++++++++++++++++++=0A> ____________= ___________________________________=0A> freebsd-questions@freebsd.org mai= ling list=0A> https://lists.freebsd.org/mailman/listinfo/freebsd-question= s=0A> To unsubscribe, send any mail to "freebsd-questions-unsubscribe@fre= ebsd.org"