Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Key rotation #350

Closed
link2xt opened this issue Feb 19, 2024 · 2 comments
Closed

Key rotation #350

link2xt opened this issue Feb 19, 2024 · 2 comments

Comments

@link2xt
Copy link

link2xt commented Feb 19, 2024

I don't see it anywhere in the documentation. Does acmetool rotate the keys ever or does it generate a single key and then renews certificates for the same key forever?

@mnalis
Copy link

mnalis commented Feb 21, 2024

As far as I can tell, it generates new private key on every certificate renewal (i.e. every 2 months)

@link2xt
Copy link
Author

link2xt commented Feb 23, 2024

Account key in /var/lib/acme/accounts/acme-v02.api.letsencrypt.org%2fdirectory/*/privkey seems to be never rotated.
/var/lib/acme/live/<domain>/privkey points to a recently created key in /var/lib/acme/keys/ but old keys in /var/lib/acme/keys/ seem to be never removed.

@link2xt link2xt closed this as completed Feb 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants