# How to regenerate SSL certificate

**URL:** <https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538>\
**Category:** Issues with deployment\
**Tags:** v2\
**Created:** [July 20, 2020, 10:29am UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538 "2020-07-20T10:29:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gaurav\_Gupta](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/gaurav_gupta/32/772_2.png) [@Gaurav\_Gupta](https://openvidu.discourse.group/u/Gaurav_Gupta)\
**Post date:** [July 20, 2020, 10:29am UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/1 "2020-07-20T10:29:15Z")

</div>

Every 3 months the SSL certificate is expired So I needs to regenerate it. I also generated new one. But I think I miss some steps to apply this in my website. Can you help me to use this.

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [July 20, 2020, 11:04am UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/2 "2020-07-20T11:04:45Z")

</div>

In OpenVidu \>2.15.0 version, SSL certificates for letsencrypt are updated automatically

---

<div class="post-metadata">

**Author:** ![vipin\_mishra](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/vipin_mishra/32/32_2.png) [@vipin\_mishra](https://openvidu.discourse.group/u/vipin_mishra)\
**Post date:** [July 21, 2020, 10:02am UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/3 "2020-07-21T10:02:39Z")

</div>

but if you want to regenerate it manually using Certboat  
certbot-auto renew --dry-run make it auto renew using crontab  
for info google it.  
But i think for openvidu 2.15.0 don’t need as @cruizba said but for your another application you have to configure yourself  
Thanks’

---

<div class="post-metadata">

**Author:** ![tomasz](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@tomasz](https://openvidu.discourse.group/u/tomasz)\
**Post date:** [July 24, 2020, 11:10am UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/4 "2020-07-24T11:10:10Z")

</div>

for **MANUAL LET’S ENCRYPT REGENARATION** (assuming you have the docker-based installation \>= 2.13):

just delete/rename the “certificates” subfolder and start openvidu again

details in this thread:

> [@No connection to OpenVidu Server. This may be a certificate error](https://openvidu.discourse.group/t/no-connection-to-openvidu-server-this-may-be-a-certificate-error/1516/6):
>
> In OpenVidu 2.15.1 it is not necessary to renew letsencrypt, it is atuomatically updated. From versions \<2.14.0 it is necessary to renew it by hand. Anyways, if you’re using version 2.15.1 You just need to start OpenVidu with your email for letsencrypt (LETSENCRYPT\_EMAIL=\<your\_email\>) and your certificate type (CERTIFICATE\_TYPE=letsencrypt) configured in your .env file. This will create a folder in /opt/openvidu/certificates with all the files necessary when you execute ./openvidu start So, if…

---

<div class="post-metadata">

**Author:** ![OgtayTasinov](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/ogtaytasinov/32/1192_2.png) [@OgtayTasinov](https://openvidu.discourse.group/u/OgtayTasinov)\
**Post date:** [January 20, 2021, 6:47pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/5 "2021-01-20T18:47:00Z")

</div>

I have deployed Openvidu 2.15.1 and monitoring SSL certificate status by Nagios. Everyday it throws warning message about certificate (letsencrypt) expiration in 1 months or so. Based on above discussion I just want to be sure if I have to do something at this point. Do I have to wait till openvidu regenerates certificate or there is any further things should be done?

---

<div class="post-metadata">

**Author:** ![vipin\_mishra](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/vipin_mishra/32/32_2.png) [@vipin\_mishra](https://openvidu.discourse.group/u/vipin_mishra)\
**Post date:** [January 20, 2021, 7:51pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/6 "2021-01-20T19:51:49Z")

</div>

i think openvidu use automatic ssl certificate renewal so don’t worry about it  
Thanks  
Vipin

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [January 21, 2021, 12:18pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/7 "2021-01-21T12:18:26Z")

</div>

Something is wrong, it should not notify about expiration.

Maybe you’ve updated the infra from older versions and the nginx container did not configured correctly autorenews. What I recommend is to regenerate the certificates again.

1. SSH into OpenVidu machine
2. Remove /opt/openvidu/certificates
3. Restart openvidu:

```auto
sudo su
cd /opt/openvidu
./openvidu restart

```

Regards,  
Carlos

---

<div class="post-metadata">

**Author:** ![OgtayTasinov](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/ogtaytasinov/32/1192_2.png) [@OgtayTasinov](https://openvidu.discourse.group/u/OgtayTasinov)\
**Post date:** [January 21, 2021, 4:06pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/8 "2021-01-21T16:06:36Z")

</div>

Hi @cruizba. Thank you for reply. I have created totally new openvidu instance with CloudFormation template provided. Do you mean nagios should not alert or openvidu itself? I received alert form nagios since it checks SSL certificate expiration time. I have noticed on doc for 2.15.1 version, it auto regenerates certificate when it expires. But wanted to be sure if it is so. Because in production it can be headache till certificate regeneration is completed manually.

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [January 21, 2021, 4:14pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/9 "2021-01-21T16:14:56Z")

</div>

Your Nagios should not alert about certificate expirations because OpenVidu Nginx container has an autorenew crontab which renews the certificate every 12 hours: [openvidu/entrypoint.sh at master · OpenVidu/openvidu · GitHub](https://github.com/OpenVidu/openvidu/blob/master/openvidu-server/docker/openvidu-proxy/entrypoint.sh#L151).

If you’re running OpenVidu with nginx running with `CERTIFICATE_TYPE=letsencrypt` option it should do the task for you.

If you still facing notifications from Nagios with your new deployment, please report it here.

---

<div class="post-metadata">

**Author:** ![OgtayTasinov](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/ogtaytasinov/32/1192_2.png) [@OgtayTasinov](https://openvidu.discourse.group/u/OgtayTasinov)\
**Post date:** [January 21, 2021, 4:40pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/10 "2021-01-21T16:40:28Z")

</div>

@cruizba I have configured it to alert as Warning (45 days), Critical (15 days). That is why it keeps alerting us every day that certificate is expiring in (45-n) days. But if you say it should not alert and should renew cert every 12 hours I dont know what to do about that. Please let me know steps I should take.

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [January 21, 2021, 5:05pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/11 "2021-01-21T17:05:26Z")

</div>

If you’ve redeployed, it should be fixed, can’t do much though. Let’s wait to see if it notify you again.

---

<div class="post-metadata">

**Author:** ![OgtayTasinov](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/ogtaytasinov/32/1192_2.png) [@OgtayTasinov](https://openvidu.discourse.group/u/OgtayTasinov)\
**Post date:** [January 21, 2021, 5:07pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/12 "2021-01-21T17:07:22Z")

</div>

@cruizba could you please let me know the location of that cronjob so I can check if everything looks good.

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [January 21, 2021, 5:07pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/13 "2021-01-21T17:07:23Z")

</div>

If autorenew is working, there should be logs in `/var/log/cron-letsencrypt.log` inside of the nginx container after 12 hours.

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [January 21, 2021, 5:12pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/14 "2021-01-21T17:12:43Z")

</div>

This command should show you the crontab command:

```auto
sudo docker exec -it openvidu_nginx_1 crontab -l

```

If you want to test if the autorenew is working execute this:

```auto
sudo docker exec -it openvidu_nginx_1 certbot renew --post-hook "nginx -s reload"

```

It should return something like that if you’ve deployed some hours ago:

```auto
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/<YOUR_DOMAIN>.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Cert not yet due for renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

The following certs are not due for renewal yet:
  /etc/letsencrypt/live/<YOUR_DOMAIN>/fullchain.pem expires on 2021-04-01 (skipped)
No renewals were attempted.
No hooks were run.
- - - - - - - - - 

```

---

<div class="post-metadata">

**Author:** ![OgtayTasinov](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/ogtaytasinov/32/1192_2.png) [@OgtayTasinov](https://openvidu.discourse.group/u/OgtayTasinov)\
**Post date:** [January 21, 2021, 5:20pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/15 "2021-01-21T17:20:56Z")

</div>

@cruizba As I understood it runs cronjob every 12 hours and checks if cert if expired or not. If Cert has not expired yet it shows “No renewals were attempted. No hooks were run.” If cert expires then renews it. Because I have deployed openvidu more than 1 month ago.

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [January 21, 2021, 5:28pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/16 "2021-01-21T17:28:25Z")

</div>

> As I understood it runs cronjob every 12 hours

Yes

> checks if cert if expired or not

No. It always try to renew. So if your certificate have 30 days before being invalidated, this command will be executed successfully.

I think that’s the problem. You have the alert 45 days before the certificate will be expired, and letsencrypt let you renew the certificate 30 days before.

I would decrease your warning alarm to 29 days.

This crontab will try to renew the certificate each 12 hours, but it will not be renewed until the certificate have 30 days to expire.

References: [[SOLVED] How often to renew? - #2 by pfg - Help - Let's Encrypt Community Support](https://community.letsencrypt.org/t/solved-how-often-to-renew/13678/2)

Regards

---

<div class="post-metadata">

**Author:** ![OgtayTasinov](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/ogtaytasinov/32/1192_2.png) [@OgtayTasinov](https://openvidu.discourse.group/u/OgtayTasinov)\
**Post date:** [January 21, 2021, 5:37pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/17 "2021-01-21T17:37:17Z")

</div>

Now it is clear. Thank you for clarification @cruizba

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [January 21, 2021, 5:48pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/18 "2021-01-21T17:48:53Z")

</div>

You’re welcome @OgtayTasinov🙂

---

<div class="post-metadata">

**Author:** ![vipin\_mishra](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/vipin_mishra/32/32_2.png) [@vipin\_mishra](https://openvidu.discourse.group/u/vipin_mishra)\
**Post date:** [January 22, 2021, 4:18am UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/19 "2021-01-22T04:18:48Z")

</div>

As I said there is no problem renewal but there is warning message  
Looks like this also gone 😀

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [January 22, 2021, 2:17pm UTC](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538/20 "2021-01-22T14:17:50Z")

</div>

Yep @vipin_mishra, thanks. You was right. I just wanted to be sure there was no other problem involved. Bugs happens you know 🙂

Regards

[Next page](https://openvidu.discourse.group/t/how-to-regenerate-ssl-certificate/1538.md?page=2)
