Skip to content

Let's encrypt fails to renew certs #3332

Description

@hb9eue

Describe the issue you are experiencing

Every 3 months, I am locked out of the HA web-gui because the let's encrypt cert expired.

I then have to log in on the HAOS console, edit configuration.yaml, comment out ssl, restart core, login without ssl, run the plug-in, comment in ssl in the config, fixed.

To my understanding, the add-on should be run daily to make sure the cert is renewed when it is bound to expire.

Maybe I am missing something? Maybe I have to install a cronjob somehow?

What type of installation are you running?

Home Assistant OS

Which operating system are you running on?

Home Assistant Operating System

Which add-on are you reporting an issue with?

Let's Encrypt

What is the version of the add-on?

5.0.1

Steps to reproduce the issue

  1. Install a let's encrypt cert using add-on.
  2. Wait 3 months for the cert to expire.
  3. No renewal happens, locked out!

System Health information

System Information

version core-2023.11.3
installation_type Home Assistant OS
dev false
hassio true
docker true
user root
virtualenv false
python_version 3.11.6
os_name Linux
os_version 6.1.59
arch x86_64
timezone Europe/Zurich
config_dir /config
Home Assistant Community Store
GitHub API ok
GitHub Content ok
GitHub Web ok
GitHub API Calls Remaining 4894
Installed Version 1.33.0
Stage running
Available Repositories 1338
Downloaded Repositories 3
Home Assistant Cloud
logged_in false
can_reach_cert_server ok
can_reach_cloud_auth ok
can_reach_cloud ok
Home Assistant Supervisor
host_os Home Assistant OS 11.1
update_channel stable
supervisor_version supervisor-2023.11.3
agent_version 1.6.0
docker_version 24.0.6
disk_total 30.8 GB
disk_used 9.6 GB
healthy true
supported true
board ova
supervisor_api ok
version_api ok
installed_addons Let's Encrypt (5.0.1), Studio Code Server (5.14.2), Advanced SSH & Web Terminal (16.0.1), Whisper (1.0.0), Piper (1.4.0)
Dashboards
dashboards 2
resources 0
views 5
mode storage
Recorder
oldest_recorder_run 11. November 2023 um 10:40
current_recorder_run 25. November 2023 um 08:51
estimated_db_size 217.00 MiB
database_engine sqlite
database_version 3.41.2
Spotify
api_endpoint_reachable ok

Anything in the Supervisor logs that might be useful for us?

23-11-25 08:50:55 INFO (MainThread) [supervisor.mounts.manager] Initializing all user-configured mounts
23-11-25 08:50:55 INFO (MainThread) [supervisor.mounts.mount] Mount PlutoBackup still activating, waiting up to 30 seconds to complete
23-11-25 08:51:05 INFO (MainThread) [supervisor.docker.monitor] Started docker events monitor
23-11-25 08:51:05 INFO (MainThread) [supervisor.updater] Fetching update data from https://version.home-assistant.io/stable.json
23-11-25 08:51:05 INFO (MainThread) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/amd64-hassio-cli with version 2023.10.0
23-11-25 08:51:06 INFO (MainThread) [supervisor.plugins.cli] Starting CLI plugin
23-11-25 08:51:06 INFO (SyncWorker_0) [supervisor.docker.manager] Cleaning hassio_cli application
23-11-25 08:51:10 INFO (MainThread) [supervisor.docker.cli] Starting CLI ghcr.io/home-assistant/amd64-hassio-cli with version 2023.10.0 - 172.30.32.5
23-11-25 08:51:10 INFO (MainThread) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/amd64-hassio-dns with version 2023.06.2
23-11-25 08:51:10 INFO (MainThread) [supervisor.plugins.dns] Starting CoreDNS plugin
23-11-25 08:51:10 INFO (SyncWorker_1) [supervisor.docker.manager] Cleaning hassio_dns application
23-11-25 08:51:16 INFO (MainThread) [supervisor.docker.dns] Starting DNS ghcr.io/home-assistant/amd64-hassio-dns with version 2023.06.2 - 172.30.32.3
23-11-25 08:51:16 INFO (MainThread) [supervisor.plugins.dns] Updated /etc/resolv.conf
23-11-25 08:51:16 INFO (MainThread) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/amd64-hassio-audio with version 2023.10.0
23-11-25 08:51:16 INFO (MainThread) [supervisor.plugins.audio] Starting Audio plugin
23-11-25 08:51:16 INFO (SyncWorker_0) [supervisor.docker.manager] Cleaning hassio_audio application
23-11-25 08:51:17 INFO (MainThread) [supervisor.docker.audio] Starting Audio ghcr.io/home-assistant/amd64-hassio-audio with version 2023.10.0 - 172.30.32.4
23-11-25 08:51:17 INFO (MainThread) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/amd64-hassio-observer with version 2023.06.0
23-11-25 08:51:17 INFO (MainThread) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/amd64-hassio-multicast with version 2023.06.2
23-11-25 08:51:17 INFO (MainThread) [supervisor.plugins.multicast] Starting Multicast plugin
23-11-25 08:51:17 INFO (SyncWorker_0) [supervisor.docker.manager] Cleaning hassio_multicast application
23-11-25 08:51:18 INFO (MainThread) [supervisor.docker.multicast] Starting Multicast ghcr.io/home-assistant/amd64-hassio-multicast with version 2023.06.2 - Host
23-11-25 08:51:18 INFO (MainThread) [supervisor.homeassistant.secrets] Loaded 1 Home Assistant secrets
23-11-25 08:51:18 INFO (MainThread) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/qemux86-64-homeassistant with version 2023.11.3
23-11-25 08:51:18 WARNING (MainThread) [supervisor.homeassistant.core] Watchdog found Home Assistant failed, restarting...
23-11-25 08:51:18 INFO (MainThread) [supervisor.os.manager] Detect Home Assistant Operating System 11.1 / BootSlot A
23-11-25 08:51:18 INFO (SyncWorker_1) [supervisor.docker.manager] Starting homeassistant
23-11-25 08:51:19 INFO (MainThread) [supervisor.homeassistant.core] Wait until Home Assistant is ready
23-11-25 08:51:19 INFO (MainThread) [supervisor.store.git] Loading add-on /data/addons/git/5c53de3b repository
23-11-25 08:51:19 INFO (MainThread) [supervisor.store.git] Loading add-on /data/addons/core repository
23-11-25 08:51:19 INFO (MainThread) [supervisor.store.git] Loading add-on /data/addons/git/a0d7b954 repository
23-11-25 08:51:21 INFO (MainThread) [supervisor.store] Loading add-ons from store: 71 all - 71 new - 0 remove
23-11-25 08:51:21 INFO (MainThread) [supervisor.addons] Found 5 installed add-ons
23-11-25 08:51:21 INFO (MainThread) [supervisor.docker.interface] Attaching to homeassistant/amd64-addon-letsencrypt with version 5.0.1
23-11-25 08:51:21 INFO (MainThread) [supervisor.docker.interface] Attaching to ghcr.io/hassio-addons/vscode/amd64 with version 5.14.2
23-11-25 08:51:21 INFO (MainThread) [supervisor.docker.interface] Attaching to homeassistant/amd64-addon-piper with version 1.4.0
23-11-25 08:51:21 INFO (MainThread) [supervisor.docker.interface] Attaching to ghcr.io/hassio-addons/ssh/amd64 with version 16.0.1
23-11-25 08:51:21 INFO (MainThread) [supervisor.docker.interface] Attaching to homeassistant/amd64-addon-whisper with version 1.0.0
23-11-25 08:51:21 INFO (MainThread) [supervisor.backups.manager] Found 54 backup files
23-11-25 08:51:21 INFO (MainThread) [supervisor.discovery] Loaded 2 messages
23-11-25 08:51:21 INFO (MainThread) [supervisor.ingress] Loaded 1 ingress sessions
23-11-25 08:51:21 INFO (MainThread) [supervisor.resolution.check] Starting system checks with state setup
23-11-25 08:51:21 INFO (MainThread) [supervisor.resolution.check] System checks complete
23-11-25 08:51:21 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state setup
23-11-25 08:51:21 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-11-25 08:51:21 INFO (MainThread) [supervisor.jobs] 'ResolutionFixup.run_autofix' blocked from execution, system is not running - setup
23-11-25 08:51:21 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state setup
23-11-25 08:51:21 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-11-25 08:51:21 INFO (MainThread) [__main__] Running Supervisor
23-11-25 08:51:21 INFO (MainThread) [supervisor.os.manager] Rauc: A - marked slot kernel.0 as good
23-11-25 08:51:21 INFO (MainThread) [supervisor.addons] Phase 'initialize' starting 0 add-ons
23-11-25 08:51:21 INFO (MainThread) [supervisor.addons] Phase 'system' starting 0 add-ons
23-11-25 08:51:21 INFO (MainThread) [supervisor.addons] Phase 'services' starting 2 add-ons
23-11-25 08:51:21 INFO (SyncWorker_4) [supervisor.docker.manager] Cleaning addon_a0d7b954_vscode application
23-11-25 08:51:22 INFO (MainThread) [supervisor.docker.addon] Starting Docker add-on ghcr.io/hassio-addons/vscode/amd64 with version 5.14.2
23-11-25 08:51:22 INFO (SyncWorker_0) [supervisor.docker.manager] Cleaning addon_a0d7b954_ssh application
23-11-25 08:51:23 INFO (MainThread) [supervisor.docker.addon] Starting Docker add-on ghcr.io/hassio-addons/ssh/amd64 with version 16.0.1
23-11-25 08:51:26 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state startup
23-11-25 08:51:26 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-11-25 08:51:26 INFO (MainThread) [supervisor.store.git] Update add-on https://github.com/esphome/home-assistant-addon repository
23-11-25 08:51:26 INFO (MainThread) [supervisor.store.git] Update add-on https://github.com/home-assistant/addons repository
23-11-25 08:51:26 INFO (MainThread) [supervisor.store.git] Update add-on https://github.com/hassio-addons/repository repository
23-11-25 08:51:29 INFO (MainThread) [supervisor.homeassistant.api] Updated Home Assistant API token
23-11-25 08:51:29 INFO (MainThread) [supervisor.homeassistant.core] Home Assistant Core state changed to NOT_RUNNING
23-11-25 08:51:29 INFO (MainThread) [supervisor.store] Loading add-ons from store: 71 all - 0 new - 0 remove
23-11-25 08:51:29 INFO (MainThread) [supervisor.store] Loading add-ons from store: 71 all - 0 new - 0 remove
23-11-25 08:51:49 INFO (MainThread) [supervisor.homeassistant.core] Home Assistant Core state changed to RUNNING
23-11-25 08:51:49 INFO (MainThread) [supervisor.homeassistant.core] Detect a running Home Assistant instance
23-11-25 08:51:52 INFO (MainThread) [supervisor.core] Skipping start of Home Assistant
23-11-25 08:51:52 INFO (MainThread) [supervisor.addons] Phase 'application' starting 2 add-ons
23-11-25 08:51:53 INFO (SyncWorker_0) [supervisor.docker.manager] Cleaning addon_core_whisper application
23-11-25 08:51:54 INFO (MainThread) [supervisor.docker.addon] Starting Docker add-on homeassistant/amd64-addon-whisper with version 1.0.0
23-11-25 08:51:54 INFO (SyncWorker_2) [supervisor.docker.manager] Cleaning addon_core_piper application
23-11-25 08:51:55 INFO (MainThread) [supervisor.docker.addon] Starting Docker add-on homeassistant/amd64-addon-piper with version 1.4.0
23-11-25 08:52:27 INFO (MainThread) [supervisor.misc.tasks] All core tasks are scheduled
23-11-25 08:52:27 INFO (MainThread) [supervisor.core] Supervisor is up and running
23-11-25 08:52:27 INFO (MainThread) [supervisor.host.info] Updating local host information
23-11-25 08:52:27 INFO (MainThread) [supervisor.updater] Fetching update data from https://version.home-assistant.io/stable.json
23-11-25 08:52:27 INFO (MainThread) [supervisor.resolution.check] Starting system checks with state running
23-11-25 08:52:27 INFO (MainThread) [supervisor.resolution.checks.base] Run check for dns_server_ipv6_error/dns_server
23-11-25 08:52:27 INFO (MainThread) [supervisor.resolution.checks.base] Run check for security/core
23-11-25 08:52:27 INFO (MainThread) [supervisor.resolution.checks.base] Run check for docker_config/system
23-11-25 08:52:27 INFO (MainThread) [supervisor.resolution.checks.base] Run check for free_space/system
23-11-25 08:52:27 INFO (MainThread) [supervisor.resolution.checks.base] Run check for dns_server_failed/dns_server
23-11-25 08:52:27 INFO (MainThread) [supervisor.resolution.checks.base] Run check for multiple_data_disks/system
23-11-25 08:52:27 INFO (MainThread) [supervisor.resolution.checks.base] Run check for trust/supervisor
23-11-25 08:52:28 INFO (MainThread) [supervisor.resolution.checks.base] Run check for pwned/addon
23-11-25 08:52:28 INFO (MainThread) [supervisor.resolution.checks.base] Run check for no_current_backup/system
23-11-25 08:52:28 INFO (MainThread) [supervisor.resolution.module] Create new suggestion create_full_backup - system / None
23-11-25 08:52:28 INFO (MainThread) [supervisor.resolution.module] Create new issue no_current_backup - system / None
23-11-25 08:52:28 INFO (MainThread) [supervisor.resolution.checks.base] Run check for ipv4_connection_problem/system
23-11-25 08:52:28 INFO (MainThread) [supervisor.resolution.check] System checks complete
23-11-25 08:52:28 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state running
23-11-25 08:52:28 INFO (MainThread) [supervisor.host.services] Updating service information
23-11-25 08:52:28 INFO (MainThread) [supervisor.host.network] Updating local network information
23-11-25 08:52:28 INFO (MainThread) [supervisor.host.sound] Updating PulseAudio information
23-11-25 08:52:28 INFO (MainThread) [supervisor.host.manager] Host information reload completed
23-11-25 08:52:29 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-11-25 08:52:29 INFO (MainThread) [supervisor.resolution.fixup] Starting system autofix at state running
23-11-25 08:52:29 INFO (MainThread) [supervisor.resolution.fixup] System autofix complete

Anything in the add-on logs that might be useful for us?

s6-rc: info: service s6rc-oneshot-runner: starting
s6-rc: info: service s6rc-oneshot-runner successfully started
s6-rc: info: service fix-attrs: starting
s6-rc: info: service fix-attrs successfully started
s6-rc: info: service legacy-cont-init: starting
cont-init: info: running /etc/cont-init.d/file-structure.sh
cont-init: info: /etc/cont-init.d/file-structure.sh exited 0
s6-rc: info: service legacy-cont-init successfully started
s6-rc: info: service legacy-services: starting
services-up: info: copying legacy longrun lets-encrypt (no readiness notification)
s6-rc: info: service legacy-services successfully started
[08:39:30] INFO: Selected DNS Provider: dns-rfc2136
[08:39:30] INFO: Use propagation seconds: 60
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Renewing an existing certificate for homeassistant.woody.ch
Waiting 60 seconds for DNS changes to propagate

Successfully received certificate.
Certificate is saved at: /data/letsencrypt/live/homeassistant.woody.ch/fullchain.pem
Key is saved at:         /data/letsencrypt/live/homeassistant.woody.ch/privkey.pem
This certificate expires on 2024-02-23.
These files will be updated when the certificate renews.
NEXT STEPS:
- The certificate will need to be renewed before it expires. Certbot can automatically renew the certificate in the background, but you may need to take steps to enable that functionality. See https://certbot.org/renewal-setup for instructions.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
If you like Certbot, please consider supporting our work by:
 * Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
 * Donating to EFF:                    https://eff.org/donate-le
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
s6-rc: info: service legacy-services: stopping
s6-rc: info: service legacy-services successfully stopped
s6-rc: info: service legacy-cont-init: stopping
s6-rc: info: service legacy-cont-init successfully stopped
s6-rc: info: service fix-attrs: stopping
s6-rc: info: service fix-attrs successfully stopped
s6-rc: info: service s6rc-oneshot-runner: stopping
s6-rc: info: service s6rc-oneshot-runner successfully stopped

Additional information

Log of successfull renewal while manually running add-on after disabling ssl because of being locked out.

s6-rc: info: service s6rc-oneshot-runner: starting
s6-rc: info: service s6rc-oneshot-runner successfully started
s6-rc: info: service fix-attrs: starting
s6-rc: info: service fix-attrs successfully started
s6-rc: info: service legacy-cont-init: starting
cont-init: info: running /etc/cont-init.d/file-structure.sh
cont-init: info: /etc/cont-init.d/file-structure.sh exited 0
s6-rc: info: service legacy-cont-init successfully started
s6-rc: info: service legacy-services: starting
services-up: info: copying legacy longrun lets-encrypt (no readiness notification)
s6-rc: info: service legacy-services successfully started
[08:39:30] INFO: Selected DNS Provider: dns-rfc2136
[08:39:30] INFO: Use propagation seconds: 60
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Renewing an existing certificate for homeassistant.woody.ch
Waiting 60 seconds for DNS changes to propagate

Successfully received certificate.
Certificate is saved at: /data/letsencrypt/live/homeassistant.woody.ch/fullchain.pem
Key is saved at: /data/letsencrypt/live/homeassistant.woody.ch/privkey.pem
This certificate expires on 2024-02-23.
These files will be updated when the certificate renews.
NEXT STEPS:

  • The certificate will need to be renewed before it expires. Certbot can automatically renew the certificate in the background, but you may need to take steps to enable that functionality. See https://certbot.org/renewal-setup for instructions.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions