Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Automatically remove failing renewals #1652

Open
zachol72 opened this issue Aug 31, 2020 · 3 comments
Open

Automatically remove failing renewals #1652

zachol72 opened this issue Aug 31, 2020 · 3 comments

Comments

@zachol72
Copy link

Perhaps a stupid question, but I can't find the answer...

When a renewal can't be completed, for example if a site/domain/binding is permanently removed from the server, for how long will WACS retry before the renewal is automatically removed (will it?) completely?

@WouterTinus
Copy link
Member

No mechanism is implemented to automatically cancel renewals which have been failing for a long time, so it will basically keep trying forever. Perhaps it would make sense to automatically clean them up 5~6 months after the last succesful renewal (because at that point the certificate is surely expired and there's been plenty of time for users to notice it).

But in general I'm not a big fan of automatically deleting/cancelling things as users still might want to have access to the history and/or use the configuration as a template for a new deployment etc.

If you have a high churn rate on your server (i.e. lots of websites being created and removed) and don't want to manage the renewals manually, you could use one of the order plugins: https://www.win-acme.com/reference/plugins/order/

@zachol72
Copy link
Author

zachol72 commented Sep 1, 2020

Ok, thanks. Good arguments.

May I request a setting for this (default value disabled)?

@WouterTinus WouterTinus changed the title For how long will WACS retry renew removed bindings? Automatically remove failing renewals Sep 8, 2020
@WouterTinus
Copy link
Member

I'll consider this, maybe by moving them to an archive folder or something so that it would still be possible to move them back with full history intact.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants