So my certbot renewal failed on a Friday night, SSL expired at midnight, sales flatlined all weekend. Running on Time4VPS shared plan. The "automatic renewal" was a cron job I set up in 2019 and it worked until last night. certbot logs show success but certificate still expired. I think the cron ran but something about the timezone? Server is somewhere, I'm somewhere else, midnight wasn't midnight. Could this be a daylight saving bug? Should I rewrite the renewal in Rust? Zero-cost abstractions would prevent this. Go's timezone handling is famously broken, C++ even worse. Memory safety matters for certificates too—imagine a use-after-free in your TLS handshake. Anyway how do I fix this now, it's 2am Saturday and I'm losing money.
My SSL cert expired at midnight, sales stopped
GroupStockholm said:
Something about the timezone? Server is somewhere, I'm somewhere else, midnight wasn't midnight.
Check cron timezone versus system timezone. certbot uses local time unless specified. 4-hour offset suggests your cron is UTC, server is EDT/EST. DST changed in March, cron didn't. Quick fix: set TZ=America/New_York in crontab. Long term: move renewal to systemd timer with explicit timezone. No DDoS angle here, but 4 hours of expired cert is 4 hours of attack surface.
mitigated 800Gbps before breakfast
If the cert expired at midnight and your local time was 4pm.. does that mean your customers saw the broken site for 8 hours before you noticed? I'm on RackNerd and always scared of this. Is there a simple way to check when your cert actually expires in your own timezone? I use the free SSL checker sites but they just say "valid until" not "valid until in your time."
frames, tables, still valid HTML