Sneaky change in the Renewal Threshold box interpretation
-
I noticed that change yesterday, several days after upgrading ACME to 1.2. I am not sure when it changed, maybe on Jan 28, when 1.1 was released, because I see this in the change log: "Changed renewal calculation to be based on certificate lifetime."
Now the Renewal Threshold description says "Days of remaining lifetime at which ACME will renew the certificate." I had 80 in this field because previously, the field meaning was the age of the certificate before renewal. I saw no reason to renew certificates one month before they expire, so I set this field to 80 to give them a longer life.
I would like to suggest that, when a setting acquires an opposite meaning after an update, either use a new variable/setting for this or set the existing one to undefined.
-
I hope the developers saw this post...
-
Nah, don't think so

I saw this, and it's going on for several weeks now :
This stat image is a copy of my 'munin grapher'.
The stat shows one 'green' certificate being renewed when after 60 days or when 30 days were left.
The blue one was renewed faster : when 60 days were left, so every 30 days.
That changed a while ago, as the stats show.
I didn't gave it much thought, but you're right, something changed.
I had a look when/what happened.
It did so last January 28, 2026, I found it here.
Afaik, this wasn't mentioned in the release notes.
It was probably mentioned in the acme.sh release note (the source - I didn't check that).I've understood : Let's Encrypt (and others) will bring the the '90 days' limit downwards in the nearby future.
Privacy Policy · Cookie Policy