[BlueOnyx:25481] Re: Letsencrypt email is not updated?

Michael Stauber mstauber at blueonyx.it
Sat Jun 18 11:05:48 -05 2022


Hi Brent,

> It appears that the Letencrypt email address (entered in [site] > SSL > 
> Let's Encrypt > Contact Email) may not be updating the cert.  We've been 
> receiving emails from expiry at letsencrypt.org that are sent a different 
> address than what's entered here.
> 
> Am I missing something?  Is a master entry somewhere I haven't found?

Yeah, this is a bit of a mixed bag. There is a master email address 
configured in /usr/sausalito/acme/account.conf

That is the account email address associated with your server in the 
ACME API.

However, when we register SSL certs, the acme.sh call to register the 
desired certificate substitutes the email address you specified in the 
GUI as a command line parameter. So that cert will get registered with 
whatever email address you had provided in the GUI during the request.

These email addresses (account API vs. certificate request email) can be 
different.

Information that a cert is about to expire is usually sent to the email 
address associated with the cert. Infos about API and policy changes are 
usually email to the account email.

-- 
With best regards

Michael Stauber



More information about the Blueonyx mailing list