Certbot Renewal Failing: 4 Checks Before It Expires

Symptom

certbot renew --dry-run errors; expiry date creeping closer.

Root cause

HTTP-01 challenge cannot reach your server, or config refers to a gone vhost.

Fix, in order

1. Run the dry run with verbositycertbot renew --dry-run --preferred-challenges http
2. Port 80 must be open and pointed at the right vhostcurl -I http://yourdomain/.well-known/acme-challenge/test
3. Check for duplicate vhosts or redirect loopscertbot renew --nginx # or --apache, matching your stack
4. Verify timer is enabledsystemctl list-timers | grep certbot

Prevent it coming back

Monitor certificate expiry externally (30/7-day alerts), not just certbot emails.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Managed cloud hosting

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog