renewal: by default, use a fraction of lifetime (#10207)

Previously we defaulted to renewing at 30 days before expiry, and
allowed users to customize the config file to set a different value.

Instead, we should renew when 1/3 of the lifetime is left, or for
shorter certificates (<10 days), when 1/2 of the lifetime is left.

This still allows explicitly configured values to take precedence.

---------

Co-authored-by: Will Greenberg <ifnspifn@gmail.com>
This commit is contained in:
Jacob Hoffman-Andrews
2025-03-12 10:35:59 -07:00
committed by GitHub
co-authored by Will Greenberg
parent b3bd4304f4
commit d91e552491
4 changed files with 103 additions and 25 deletions
+9 -9
View File
@@ -628,10 +628,6 @@ Follow these steps to safely delete a certificate:
Renewing certificates
---------------------
.. note:: Let's Encrypt CA issues short-lived certificates (90
days). Make sure you renew the certificates at least once in 3
months.
.. seealso:: Most Certbot installations come with automatic
renewal out of the box. See `Automated Renewals`_ for more details.
@@ -639,14 +635,18 @@ Renewing certificates
will not renew automatically, unless combined with authentication hook scripts.
See `Renewal with the manual plugin <#manual-renewal>`_.
As of version 0.10.0, Certbot supports a ``renew`` action to check
all installed certificates for impending expiry and attempt to renew
them. The simplest form is simply
Certbot supports a ``renew`` action to check all installed certificates for
impending expiry and attempt to renew them. The simplest form is simply
``certbot renew``
This command attempts to renew any previously-obtained certificates that
expire in less than 30 days. The same plugin and options that were used
This command attempts to renew any previously-obtained certificates which are ready
for renewal. As of Certbot 4.0.0, a certificate is considered ready for renewal
when less than 1/3rd of its lifetime remains. For certificates with a lifetime
of 10 days or less, that threshold is 1/2 of the lifetime. Prior to Certbot 4.0.0
the threshold was a fixed 30 days.
The same plugin and options that were used
at the time the certificate was originally issued will be used for the
renewal attempt, unless you specify other plugins or options. Unlike ``certonly``, ``renew`` acts on
multiple certificates and always takes into account whether each one is near