ACME/Certificate renewal stopped working

Started by PotatoCarl, July 16, 2026, 12:20:09 PM

Previous topic - Next topic
Hi there.
I have installed and up and running the ACME plugin on the OPNSense community edition for some years. It refreshes a certificate for a webserver that has no external access (rocket chat) and copies it via SFTP to that system, then does a few file operations to get it installed. I used the HTTP Challenge.

Earlier this year I replaced the appliance with a new one, and wen to OPNSense business edition 25.10. That did not seem to be a problem at the time, basically everthing worked fine. Later then, it upgraded to 26.4..

*However* I noticed as of today, a couple of months later, that the certificates did not get renewed. Now, my memory is probably not the best, but I am kind of 80% sure that I checked after switching to the new appliance if the certificate was updated and believe to remember it did.

When I checked the firewall rules, I found that port 80 was not open (anymore?) at the external interfaces.

Long story short, I do not get the certificates refreshed.

I tried HTTP and TLS challenge and opening the ports, then the protocol say:

HTTP challenge:

2026-07-16T12:00:36 opnsense-business
AcmeClient: AcmeClient: The shell command returned exit code '1': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 2 --server 'letsencrypt' --webroot /var/etc/acme-client/challenges --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/616731d690b683.11437695' --certpath '/var/etc/acme-client/certs/616731d690b683.11437695/cert.pem' --keypath '/var/etc/acme-client/keys/616731d690b683.11437695/private.key' --capath '/var/etc/acme-client/certs/616731d690b683.11437695/chain.pem' --fullchainpath '/var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem' --domain 'rocket.brace.de' --days '30' --force --keylength '4096' --accountconf '/var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf''

When using the TLS Challenge:

2026-07-16T12:01:06
opnsense-business
AcmeClient: AcmeClient: The shell command returned exit code '1': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 2 --server 'letsencrypt' --alpn --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/616731d690b683.11437695' --certpath '/var/etc/acme-client/certs/616731d690b683.11437695/cert.pem' --keypath '/var/etc/acme-client/keys/616731d690b683.11437695/private.key' --capath '/var/etc/acme-client/certs/616731d690b683.11437695/chain.pem' --fullchainpath '/var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem' --domain 'rocket.brace.de' --days '30' --force --keylength '4096' --tlsport '43581' --accountconf '/var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf''


Under "Accounts" it claims the account is "OK" in the status.


I was not able to find a HOWTO for setting up the DNS-01 challenge (all of them omit how to create the nsupdate key and which exact format I need to put it into the DNS TXT records) so I gave up on that. If anybody has a howto for an idiot like me to get it created and installed I'll be greatful and will try.


In the ACME Log of OPNSense however, it seem to be working all well:

2026-07-16T12:00:35 acme.sh
[Thu Jul 16 12:00:35 CEST 2026] Single domain='rocket.brace.de'
2026-07-16T12:00:35 acme.sh
[Thu Jul 16 12:00:35 CEST 2026] Using CA: https://acme-v02.api.letsencrypt.org/directory
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Installing full chain to: /var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Installing key to: /var/etc/acme-client/keys/616731d690b683.11437695/private.key
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Installing CA to: /var/etc/acme-client/certs/616731d690b683.11437695/chain.pem
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Installing cert to: /var/etc/acme-client/certs/616731d690b683.11437695/cert.pem
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] And the full-chain cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/fullchain.cer
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] The intermediate CA cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/ca.cer
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Your cert key is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.key
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Your cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.cer
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Cert success.
2026-07-16T11:50:29 acme.sh
[Thu Jul 16 11:50:29 CEST 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/0517aa711b64efc1671ef56cccab97cf1583';
2026-07-16T11:50:29 acme.sh
[Thu Jul 16 11:50:29 CEST 2026] Downloading cert.
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/3539327496/532898622926';
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] Let's finalize the order.
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] Verification finished, beginning signing.
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] rocket.brace.de is already verified, skipping http-01.
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] Getting webroot for domain='rocket.brace.de'
2026-07-16T11:50:26 acme.sh
[Thu Jul 16 11:50:26 CEST 2026] Single domain='rocket.brace.de'


Shouldn't that say that the certificate was in fact renewed and should be on OPNSense? However, in the certificate section it is displayed as "überprüfung fehlgeschlagen" (renewal failed or to whatever this is translated)

Is there anything I can do to fix that?

Thanks.

Did you do the "Reset ACME client" thing after moving to the new appliance?

BTW, thanks for the reminder - I just did a new installation of 26.7 and imported my config, but I hadn't remembered this ACME reset step ;)

Follow Up: I asked some AI and it mentioned to issue the "faulty" command directly on the firefwall, which i did.

Now, it throws a couple of errormessages

ouch: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
chmod: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot open /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot create /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
touch: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
chmod: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot open /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot create /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory


It seems as the account directory is not existing at all.

If I switch the the "Testing" account at let's encrypt the acme.sh comand is successfully running (via TLS challenge even)

2026-07-16T12:32:29
opnsense-business
AcmeClient: AcmeClient: The shell command returned exit code '0': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 2 --server 'letsencrypt_test' --alpn --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/616731d690b683.11437695' --certpath '/var/etc/acme-client/certs/616731d690b683.11437695/cert.pem' --keypath '/var/etc/acme-client/keys/616731d690b683.11437695/private.key' --capath '/var/etc/acme-client/certs/616731d690b683.11437695/chain.pem' --fullchainpath '/var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem' --domain 'rocket.brace.de' --days '30' --force --keylength '4096' --tlsport '43581' --accountconf '/var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf''

BUT if I start it on the command line, I get the same error messages about the missing account:

touch: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
chmod: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot open /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot create /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
touch: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
chmod: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot open /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot create /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory

Just my thinking: is it possible that during migration from the community edition to the business edition everything BUT the accounts have been imported?


Quote from: dseven on July 16, 2026, 12:29:34 PMDid you do the "Reset ACME client" thing after moving to the new appliance?

BTW, thanks for the reminder - I just did a new installation of 26.7 and imported my config, but I hadn't remembered this ACME reset step ;)


I most definetly did not... and I am not sure how to do it? I will look for a suitable button but if you have a hint...

Current status (sorry for that but sometimes posting my problems here starts a new though process and I retry) is that it seems that the account have not been migrated. So no account information available.

I could just click at the "register account" button besides the accounts and they seem to have been recreated in the file system.

When running the command now at the command line there seem to be no error messages anymore. Unfortunately I cleverly used the "normal" account for the inital testing and Let's Encrypt is now pretty strict, locking me out for 7 days to renew the "real" certificate.

So @dseven I believe it would at this stage not a good anymore the reset. I have to recheck in 7 days if the certificate is really renewed, and then I might come back to that issue.

Thank you.


Thank you dseven.

One more thing in case somebody else has those problems. The ssh keys change, too, so they are not imported in the backup. That means, if you transfer e.g. a cert with SFTP, you must also include the new .pub key on the target system.

This never get too boring here. So, after being blocked for 168hours, I was able to reissue the certifcate. BUT and this is the problem

- The webgui and log said "all is well"
- In the "certifiacte" section it is shown as "verfication failed"
- On the command line of the opnsense router I was able to run it, and install it manually on the host in question. So the certificate is fine
- "Reimport" of the certificate does not yield the refreshed one.
- The log file of the ACME client shows it is all well

2026-07-24T14:08:15
opnsense-business
AcmeClient: imported ACME CA: YR1 (6a6355af8c3b6)
2026-07-24T13:46:01
opnsense-business
AcmeClient: running automation (configd): Change_rights_Certificate
2026-07-24T13:46:01
opnsense-business
AcmeClient: running automation (configd): Change_Ownership_Certificate
2026-07-24T13:45:59
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-iKI0mG' to 'rocket.brace.de.key.pem'
2026-07-24T13:45:59
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.key.pem'
2026-07-24T13:45:58
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-6pka5k' to 'rocket.brace.de.fullchain.pem'
2026-07-24T13:45:58
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.fullchain.pem'
2026-07-24T13:45:57
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-94mTkH' to 'rocket.brace.de.cert.pem'
2026-07-24T13:45:57
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.cert.pem'
2026-07-24T13:45:56
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-oKGIEZ' to 'rocket.brace.de.ca.pem'
2026-07-24T13:45:56
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.ca.pem'
2026-07-24T13:45:51
opnsense-business
AcmeClient: running automation (configd): CopyCerts2Rocket
2026-07-24T13:45:51
opnsense-business
AcmeClient: running automations for certificate: rocket.brace.de
2026-07-24T13:45:47
opnsense-business
AcmeClient: imported ACME CA: YR1 (6a63506bbeb80)
2026-07-24T13:45:23
opnsense-business
AcmeClient: running automation (configd): Change_rights_Certificate
2026-07-24T13:45:22
opnsense-business
AcmeClient: running automation (configd): Change_Ownership_Certificate
2026-07-24T13:45:21
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-01Qt4t' to 'rocket.brace.de.key.pem'
2026-07-24T13:45:21
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.key.pem'
2026-07-24T13:45:20
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-nR04tT' to 'rocket.brace.de.fullchain.pem'
2026-07-24T13:45:20
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.fullchain.pem'
2026-07-24T13:45:19
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-0eqr8Z' to 'rocket.brace.de.cert.pem'
2026-07-24T13:45:19
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.cert.pem'
2026-07-24T13:45:17
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-o7Dai8' to 'rocket.brace.de.ca.pem'
2026-07-24T13:45:17
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.ca.pem'
2026-07-24T13:45:13
opnsense-business
AcmeClient: running automation (configd): CopyCerts2Rocket
2026-07-24T13:45:13
opnsense-business
AcmeClient: running automations for certificate: rocket.brace.de
2026-07-24T13:43:20
opnsense-business
AcmeClient: imported ACME CA: YR1 (6a634fd8e17a9)
2026-07-24T13:43:20
opnsense-business
AcmeClient: successfully issued/renewed certificate: rocket.brace.de
2026-07-24T13:43:18
opnsense-business
AcmeClient: AcmeClient: The shell command returned exit code '0': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 2 --server 'letsencrypt' --alpn --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/616731d690b683.11437695' --certpath '/var/etc/acme-client/certs/616731d690b683.11437695/cert.pem' --keypath '/var/etc/acme-client/keys/616731d690b683.11437695/private.key' --capath '/var/etc/acme-client/certs/616731d690b683.11437695/chain.pem' --fullchainpath '/var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem' --domain 'rocket.brace.de' --days '30' --force --keylength '4096' --tlsport '43581' --accountconf '/var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf''
2026-07-24T13:43:12
opnsense-business
AcmeClient: using challenge type: HTTP-Challenge_TLS
2026-07-24T13:43:12
opnsense-business
AcmeClient: using IPv4 address: 192.168.179.40
2026-07-24T13:43:12
opnsense-business
AcmeClient: using IPv4 address: 87.191.224.208
2026-07-24T13:43:12
opnsense-business
AcmeClient: using IPv4 address: 217.91.66.204
2026-07-24T13:43:12
opnsense-business
AcmeClient: account config is valid (CERT_HOME): BRACE_OPN
2026-07-24T13:43:12
opnsense-business
AcmeClient: account is registered: BRACE_OPN
2026-07-24T13:43:12
opnsense-business
AcmeClient: using CA: letsencrypt
2026-07-24T13:43:12
opnsense-business
AcmeClient: issue certificate: rocket.brace.de
2026-07-24T00:00:01
opnsense-business
AcmeClient: ignoring disabled certificate: directory1.brace.de
2026-07-24T00:00:00
opnsense-business
AcmeClient: ignoring disabled certificate: rocket.brace.de
2026-07-24T00:00:00
opnsense-business
AcmeClient: ignoring disabled certificate: rocket.brace.de
2026-07-24T00:00:00
opnsense-business
AcmeClient: ignoring disabled certificate: groupware.brace.de
2026-07-24T00:00:00
opnsense-business
AcmeClient: issue/renewal not required for certificate: rocket.brace.de

In the firewall log however I get those errormessages:

The DNS query name does not exist: acme-v01-2.api.letsencrypt.org. [for Letsencrypt_certbot]
I cannot access these sites via browser.

The ACME.log also seems to be doing well:
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Installing full chain to: /var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Installing key to: /var/etc/acme-client/keys/616731d690b683.11437695/private.key
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Installing CA to: /var/etc/acme-client/certs/616731d690b683.11437695/chain.pem
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Installing cert to: /var/etc/acme-client/certs/616731d690b683.11437695/cert.pem
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] And the full-chain cert is in: ␛[1;32m/var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/fullchain.cer␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] The intermediate CA cert is in: ␛[1;32m/var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/ca.cer␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Your cert key is in: ␛[1;32m/var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.key␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Your cert is in: ␛[1;32m/var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.cer␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] ␛[1;32mCert success.␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/058280df044c612c1ee8ad643b58f2c49a06';
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Downloading cert.
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/237870340/536133903845';
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] Let's finalize the order.
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] Verification finished, beginning signing.
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] rocket.brace.de is already verified, skipping tls-alpn-01.
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] Getting webroot for domain='rocket.brace.de'
2026-07-24T13:45:24
acme.sh
[Fri Jul 24 13:45:24 CEST 2026] Single domain='rocket.brace.de'
2026-07-24T13:45:24
acme.sh
[Fri Jul 24 13:45:23 CEST 2026] Standalone alpn mode.
2026-07-24T13:45:23
acme.sh
[Fri Jul 24 13:45:23 CEST 2026] Using CA: https://acme-v02.api.letsencrypt.org/directory
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Installing full chain to: /var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Installing key to: /var/etc/acme-client/keys/616731d690b683.11437695/private.key
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Installing CA to: /var/etc/acme-client/certs/616731d690b683.11437695/chain.pem
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Installing cert to: /var/etc/acme-client/certs/616731d690b683.11437695/cert.pem
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] And the full-chain cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/fullchain.cer
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] The intermediate CA cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/ca.cer
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Your cert key is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.key
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Your cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.cer
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Cert success.
2026-07-24T13:43:17
acme.sh
[Fri Jul 24 13:43:17 CEST 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/053ad6410a898d89bb5327782351246cd6e0';
2026-07-24T13:43:17
acme.sh
[Fri Jul 24 13:43:17 CEST 2026] Downloading cert.
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/237870340/536133362855';
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] Let's finalize the order.
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] Verification finished, beginning signing.
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] rocket.brace.de is already verified, skipping tls-alpn-01.
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] Getting webroot for domain='rocket.brace.de'
2026-07-24T13:43:13
acme.sh
[Fri Jul 24 13:43:13 CEST 2026] Single domain='rocket.brace.de'
2026-07-24T13:43:13
acme.sh
[Fri Jul 24 13:43:13 CEST 2026] Standalone alpn mode.


I did not reset the ACME client after update - please correct me if I am wrong - as it does not seem to be necessary. In the file system the correct certificate is stored. So where might be the problem here? Any ideas?