Let's Encrypt certs last 90 days and certbot renews via a cron/systemd timer — until something small breaks it. Test renewals before you need them.
HTTP-01 needs /.well-known/acme-challenge reachable on port 80. A redirect loop or firewall breaks it.
systemd timer masked, or the deploy hook that reloads nginx errors and the new cert never activates.
You moved servers or proxied the domain; the challenge now hits the wrong box.
certbot renew --dry-run
systemctl list-timers | grep certbot
certbot certonly --preferred-challenges dns -d yourdomain.com
--deploy-hook 'systemctl reload nginx'
Behind Cloudflare, use a DNS-01 challenge with an API token: no port-80 exposure, works for wildcards, and survives origin moves.
certbot renew --dry-run uses the staging endpoint: it exercises the whole auth path without touching your real quota or certificates. It's the definitive pre-flight test.
No — the current certificate keeps serving until it actually expires. Renewal failures warn for days (certbot tries twice daily) before the real deadline, which is why alerting on renewal failures matters more than the failure itself.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.