<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Problem with getting letsencrypt renewal - General Info				            </title>
            <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/</link>
            <description>Zextras Community Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Tue, 08 Sep 2026 00:24:45 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-12209</link>
                        <pubDate>Fri, 27 Mar 2026 11:42:05 +0000</pubDate>
                        <description><![CDATA[@mrmastii 
You reported this:
When I run certbot from command line I am getting this error:
$ certbotAn unexpected error occurred:KeyError: &#039;manual&#039;Ask for help or searc...]]></description>
                        <content:encoded><![CDATA[<p>@mrmastii </p>
<p>You reported this:</p>
<p>When I run certbot from command line I am getting this error:</p>
<p>$ certbot<br />An unexpected error occurred:<br />KeyError: 'manual'<br />Ask for help or search for solutions at <a class="wpforo-auto-embeded-link" href="https://community.letsencrypt.org." target="_blank" rel="nofollow noopener">https://community.letsencrypt.org.</a> See the logfile /tmp/certbot-log-6yuviekg/log or re-run Certbot with -v for more details</p>
<p>Did you get this issue fixed?<br />If yes, then how?</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>hwoffinden</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-12209</guid>
                    </item>
				                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10331</link>
                        <pubDate>Thu, 17 Apr 2025 10:11:58 +0000</pubDate>
                        <description><![CDATA[@liopardo
Hi,
I can understand your concern, hence it needs further investigation to conclude anything. let&#039;s see.&#x1f60a;]]></description>
                        <content:encoded><![CDATA[<p>@<span>liopardo</span></p>
<p>Hi,</p>
<p>I can understand your concern, hence it needs further investigation to conclude anything. let's see.&#x1f60a;</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>Sharif</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10331</guid>
                    </item>
				                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10330</link>
                        <pubDate>Thu, 17 Apr 2025 08:55:02 +0000</pubDate>
                        <description><![CDATA[@sharif 
Thanks for the replay. I&#039;ll be able to check later.
But do you think that it doesn&#039;t affect the correct renewal functioning that with input zmcontrol status it results 
certbot.t...]]></description>
                        <content:encoded><![CDATA[<p>@sharif </p>
<p>Thanks for the replay. I'll be able to check later.</p>
<p>But do you think that it doesn't affect the correct renewal functioning that with input zmcontrol status it results </p>
<pre contenteditable="false">certbot.timer Stopped</pre>
<p>Thanks</p>
<p>Fabio</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>liopardo</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10330</guid>
                    </item>
				                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10328</link>
                        <pubDate>Thu, 17 Apr 2025 08:00:47 +0000</pubDate>
                        <description><![CDATA[@liopardo 
Hi,
Now it should work. Let us know how it goes.]]></description>
                        <content:encoded><![CDATA[<p>@liopardo </p>
<p>Hi,</p>
<p>Now it should work. Let us know how it goes.</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>Sharif</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10328</guid>
                    </item>
				                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10325</link>
                        <pubDate>Wed, 16 Apr 2025 12:47:45 +0000</pubDate>
                        <description><![CDATA[@sharif 
root@mail ~ # root@mail ~ # systemctl start carbonio-certbot.timerroot@mail ~ # systemctl enable carbonio-certbot.timerroot@mail ~ # root@mail ~ # root@mail ~ # systemctl status ca...]]></description>
                        <content:encoded><![CDATA[<p>@sharif </p>
<p>root@mail ~ # <br />root@mail ~ # systemctl start carbonio-certbot.timer<br />root@mail ~ # systemctl enable carbonio-certbot.timer<br />root@mail ~ # <br />root@mail ~ # <br />root@mail ~ # systemctl status carbonio-certbot.timer<br />● carbonio-certbot.timer - Run Carbonio Certbot twice daily<br />Loaded: loaded (/lib/systemd/system/carbonio-certbot.timer; enabled; vendor preset: enabled)<br />Active: active (waiting) since Wed 2025-04-16 09:09:39 UTC; 3h 35min ago<br />Trigger: Thu 2025-04-17 09:49:10 UTC; 21h left<br />Triggers: ● carbonio-certbot.service<br /><br />Apr 16 09:09:39 mail.liopardo.eu systemd: Started Run Carbonio Certbot twice daily.<br />root@mail ~ # <br />root@mail ~ # <br />root@mail ~ # <br />root@mail ~ # systemctl list-timers carbonio-certbot.timer<br />NEXT LEFT LAST PASSED UNIT ACTIVATES <br />Thu 2025-04-17 09:49:10 UTC 21h left Wed 2025-04-16 12:13:21 UTC 32min ago carbonio-certbot.timer carbonio-certbot.service<br /><br />1 timers listed.<br />Pass --all to see loaded but inactive timers, too.<br />root@mail ~ # <br />root@mail ~ # <br />root@mail ~ # <br />root@mail ~ # journalctl -u carbonio-certbot.timer<br />Apr 16 09:04:45 mail.liopardo.eu systemd: carbonio-certbot.timer: Deactivated successfully.<br />Apr 16 09:04:45 mail.liopardo.eu systemd: Stopped Run Carbonio Certbot twice daily.<br />-- Boot b3cb5f938a8041a4b9c4611d8d61cbc9 --<br />Apr 16 09:09:39 mail.liopardo.eu systemd: Started Run Carbonio Certbot twice daily.<br />root@mail ~ # <br />root@mail ~ # <br />root@mail ~ # su zextras<br />To run a command as administrator (user "root"), use "sudo &lt;command&gt;".<br />See "man sudo_root" for details.<br /><br />zextras@mail:/root$ zmcontrol status<br />Host mail.liopardo.eu<br />amavis Running<br />antispam Running<br />antivirus Running<br />cbpolicyd Running<br />certbot.timer Stopped<br />directory-server Running<br />mailbox Running<br />memcached Running<br />mta Running<br />opendkim Running<br />proxy Running<br />service webapp Running<br />service-discover Running<br />stats Running<br />config service Running</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>liopardo</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10325</guid>
                    </item>
				                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10324</link>
                        <pubDate>Wed, 16 Apr 2025 12:22:05 +0000</pubDate>
                        <description><![CDATA[@liopardo 
Hi,
Try this:

Start the timer
Enable it (if needed)
See the status

For example:
root@mail:~# systemctl start carbonio-certbot.timer
root@mail:~# systemctl enable carbo...]]></description>
                        <content:encoded><![CDATA[<p>@liopardo </p>
<p>Hi,</p>
<p>Try this:</p>
<ul>
<li>Start the timer</li>
<li>Enable it (if needed)</li>
<li>See the status</li>
</ul>
<p>For example:</p>
<pre contenteditable="false">root@mail:~# systemctl start carbonio-certbot.timer
root@mail:~# systemctl enable carbonio-certbot.timer</pre>
<p>&amp;</p>
<pre contenteditable="false">root@mail:~# systemctl status carbonio-certbot.timer
● carbonio-certbot.timer - Run Carbonio Certbot twice daily
     Loaded: loaded (/lib/systemd/system/carbonio-certbot.timer; enabled; vendor preset: enabled)
     Active: active (running) since Tue 2025-04-15 17:47:48 +06; 24h ago
    Trigger: n/a
   Triggers: ● carbonio-certbot.service

Apr 15 17:47:48 mail.demo-carbonioce.com systemd: Started Run Carbonio Certbot twice daily.
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~# systemctl list-timers carbonio-certbot.timer
NEXT                        LEFT    LAST                        PASSED  UNIT                   ACTIVATES
Thu 2025-04-17 02:53:23 +06 8h left Wed 2025-04-16 18:20:03 +06 28s ago carbonio-certbot.timer carbonio-certbot.service

1 timers listed.
Pass --all to see loaded but inactive timers, too.
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~# journalctl -u carbonio-certbot.timer
Apr 11 21:58:33 mail.demo-carbonioce.com systemd: Started Run Carbonio Certbot twice daily.
Apr 15 17:43:09 mail.demo-carbonioce.com systemd: carbonio-certbot.timer: Deactivated successfully.
Apr 15 17:43:09 mail.demo-carbonioce.com systemd: Stopped Run Carbonio Certbot twice daily.
-- Boot b6fe48d3b61a4cba9e8beef3fabb8249 --
Apr 15 17:47:48 mail.demo-carbonioce.com systemd: Started Run Carbonio Certbot twice daily.
root@mail:~#
</pre>
<p> </p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>Sharif</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10324</guid>
                    </item>
				                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10320</link>
                        <pubDate>Wed, 16 Apr 2025 09:39:19 +0000</pubDate>
                        <description><![CDATA[@sharif 
Hi and thank you for your great Job
Certbot.timer each time postponed the renewal by a few hours without ever doing it
So I succesfully forced certs renew very close to expire. ...]]></description>
                        <content:encoded><![CDATA[<p>@sharif </p>
<p>Hi and thank you for your great Job</p>
<p>Certbot.timer each time postponed the renewal by a few hours without ever doing it</p>
<p>So I succesfully forced certs renew very close to expire. </p>
<p>After reboot certs are renewed and if I input zmcontrol status i obtain   certbot.timer Stopped</p>
<p>and if I input  systemctl status carbonio-certbot.service I get:</p>
<p>○ carbonio-certbot.service - Renew certificates acquired via Carbonio Certbot<br />Loaded: loaded (/lib/systemd/system/carbonio-certbot.service; static)<br />Active: inactive (dead)<br />TriggeredBy: ● carbonio-certbot.timer<br />Docs: https://eff-certbot.readthedocs.io/en/stable/</p>
<p>Whats wrong?</p>
<p>Thanks</p>
<p>Fabio</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>liopardo</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-10320</guid>
                    </item>
				                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-8330</link>
                        <pubDate>Sun, 21 Jul 2024 22:10:38 +0000</pubDate>
                        <description><![CDATA[Hello,
It is very nice, not a simgle response to my problem .... and now I can&#039;t access the admin web service ...
WIll try to find by myself ...]]></description>
                        <content:encoded><![CDATA[<p>Hello,</p>
<p>It is very nice, not a simgle response to my problem .... and now I can't access the admin web service ...</p>
<p>WIll try to find by myself ...</p>
<p> </p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>jppo</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-8330</guid>
                    </item>
				                    <item>
                        <title>RE: Problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-8223</link>
                        <pubDate>Sun, 30 Jun 2024 10:02:56 +0000</pubDate>
                        <description><![CDATA[Hello,
The only solution I find was to create a new file &quot;nginx.conf.web.https.template&quot; in the directoey &quot;/opt/zextras/conf/nginx/templates_custom&quot; copy of the same file in &quot;/opt/zextras/c...]]></description>
                        <content:encoded><![CDATA[<p>Hello,</p>
<p>The only solution I find was to create a new file "nginx.conf.web.https.template" in the directoey "/opt/zextras/conf/nginx/templates_custom" copy of the same file in "/opt/zextras/conf/nginx/templates".</p>
<p>I modify the lines (23/24) :</p>
<p>ssl_certificate ${ssl.crt};<br />ssl_certificate_key ${ssl.key};</p>
<p>to :</p>
<p>ssl_certificate /opt/zextras/conf/nginx.crt;<br />ssl_certificate_key /opt/zextras/conf/nginx.key;</p>
<p>Restarting the proxy : "zmproxyctl restart" and ... the web app is OK, from PC as from the Iphone application.</p>
<p>I hope this will help somebody.</p>
<p>I think that it is a small bug (?).</p>
<p>Regards</p>
<p>JP P</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>jppo</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-8223</guid>
                    </item>
				                    <item>
                        <title>Always problem with getting letsencrypt renewal</title>
                        <link>https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-8221</link>
                        <pubDate>Sat, 29 Jun 2024 11:02:18 +0000</pubDate>
                        <description><![CDATA[Hello,
The certificate verification is OK :
/opt/zextras/libexec/zmcheckexpiredcerts -days 30 -verbose -mailto jpp@jpp.frldap: notAfter=Sep 8 13:23:43 2024 GMT &#039;/opt/zextras/conf/slapd.crt...]]></description>
                        <content:encoded><![CDATA[<p>Hello,</p>
<p>The certificate verification is OK :</p>
<p>/opt/zextras/libexec/zmcheckexpiredcerts -days 30 -verbose -mailto jpp@jpp.fr<br />ldap: notAfter=Sep 8 13:23:43 2024 GMT '/opt/zextras/conf/slapd.crt' expires outside of 30 days (OK)<br />mailboxd: notAfter=Sep 8 13:23:43 2024 GMT '/opt/zextras/mailboxd/etc/mailboxd.pem' expires outside of 30 days (OK)<br />mta: notAfter=Sep 8 13:23:43 2024 GMT '/opt/zextras/conf/smtpd.crt' expires outside of 30 days (OK)<br />proxy: notAfter=Sep 8 13:23:43 2024 GMT '/opt/zextras/conf/nginx.crt' expires outside of 30 days (OK)</p>
<p>But when I try to connect to the web service I get always :</p>
<p><span style="color: #5f6368;font-size: 15.9375px;font-style: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;background-color: #ffffff;display: inline !important;float: none">This server could not prove that it is<span> </span></span><strong style="color: #5f6368;font-size: 15.9375px;font-style: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;background-color: #ffffff">mail.jppozzi.dyndns.org</strong><span style="color: #5f6368;font-size: 15.9375px;font-style: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;background-color: #ffffff;display: inline !important;float: none">; its security certificate expired 13 days ago.<span> </span></span></p>
<p>The file "/opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.crt and the key" are always ending on 16/06/2024 and renewed every day at 00:00 and that file is used in all nginx config files :</p>
<p>./includes/nginx.conf.mail.imaps: server_name mail.jppozzi.dyndns.org;<br />./includes/nginx.conf.mail.imaps: ssl_certificate /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.crt;<br />./includes/nginx.conf.mail.imaps: ssl_certificate_key /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.key;<br />./includes/nginx.conf.mail.imap: server_name mail.jppozzi.dyndns.org;<br />./includes/nginx.conf.mail.imap: ssl_certificate /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.crt;<br />./includes/nginx.conf.mail.imap: ssl_certificate_key /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.key;<br />./includes/nginx.conf.mail.pop3: server_name mail.jppozzi.dyndns.org;<br />./includes/nginx.conf.mail.pop3: ssl_certificate /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.crt;<br />./includes/nginx.conf.mail.pop3: ssl_certificate_key /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.key;<br />./includes/nginx.conf.web.admin: server_name mail.jppozzi.dyndns.org;<br />./includes/nginx.conf.web.admin: ssl_certificate /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.crt;<br />./includes/nginx.conf.web.admin: ssl_certificate_key /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.key;<br />./includes/nginx.conf.mail.pop3s: server_name mail.jppozzi.dyndns.org;<br />./includes/nginx.conf.mail.pop3s: ssl_certificate /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.crt;<br />./includes/nginx.conf.mail.pop3s: ssl_certificate_key /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.key;<br />./includes/nginx.conf.map.crt:mail.jppozzi.dyndns.org /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.crt;<br />./includes/nginx.conf.web.https: server_name mail.jppozzi.dyndns.org;<br />./includes/nginx.conf.web.https: ssl_certificate /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.crt;<br />./includes/nginx.conf.web.https: ssl_certificate_key /opt/zextras/conf/domaincerts/mail.jppozzi.dyndns.org.key;</p>
<p>From what files are that files copied ?</p>
<p> </p>
<p>Regards</p>
<p>JP P</p>
<p> </p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>jppo</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/problem-with-getting-letsencrypt-renewal/paged/2/#post-8221</guid>
                    </item>
							        </channel>
        </rss>
		