Skip to content
DnsLister Forum

Where domain hunters compare notes

How do you test Caddy certificate renewal before the real expiry window?

Automatic HTTPS removes most certificate work, but a deployment can still carry a latent renewal failure for weeks: DNS credentials may have changed, a challenge port may be blocked, the storage location may no longer be writable, or a cluster member may not share certificate state as expected. Waiting for the normal renewal window makes the first realistic test time-sensitive.

What is a safe rehearsal that does not disturb the production certificate or hit CA rate limits? I am considering a separate test hostname, the staging ACME endpoint, the same DNS or HTTP challenge path and credentials, an isolated Caddy storage directory, and checks that confirm issuance, persistence, reload, and access from every serving node. Monitoring would alert on remaining lifetime and the last successful automation event rather than only on expiry.

Does that exercise enough of the production path, or is there a supported way to force a renewal dry run against the existing configuration? Which parts of the rehearsal commonly give false confidence?

Source: r/caddyserver · by /u/RocketSeven

Leave a Reply

Your email address will not be published. Required fields are marked *