jcoffey-dev is traveling from Thursday 1 October through Sunday 4 October. Issues and pull requests are welcome, and will get an answer after that. Thanks for your patience.
When a valid certificate already covered a domain's names (one stored by hand before the domain was switched to automatic, say), acme_renew returned NotDue. The task manager treats that as a permanent failure, and nothing rescheduled the renewal, so the certificate later expired unrenewed. This is the trap noted when inbuxa's own domains were switched to Automatic on 2026-09-13.
Now a renewal that isn't due returns a new AcmeRenewal task due at the certificate's renewal point, exactly as a successful renewal does, and logs it as RenewBackoff. The task manager is its only caller. The certificates guide (admin #39) shows this state as already covered, renews on ….
The ACME integration suite gains a check: renewing again right after issuance returns one AcmeRenewal for that domain, due at the certificate's renewal point.
Not run yet. Please run it somewhere Pebble can reach the test server.automation::automation_tests fails on the dev laptop before the new check, at the first issuance, and it fails identically on unchanged main. ufw drops traffic from the stalwart-test-acme docker network (172.21.0.0/16) to the host, so Pebble's TLS-ALPN / HTTP-01 connections to ports 8899/8898 never arrive (confirmed with a container → host probe). To run it locally:
sudo ufw allow in on br-e9f716ec2642 to any port 8898:8899 proto tcp
STORE=RocksDb RUST_MIN_STACK=16777216 cargo test -p tests --lib -- automation::automation_tests --exact --include-ignored
cargo check -p common is clean. CI builds but doesn't run the suite.
When a valid certificate already covered a domain's names (one stored by hand before the domain was switched to automatic, say), `acme_renew` returned `NotDue`. The task manager treats that as a **permanent** failure, and nothing rescheduled the renewal, so the certificate later expired unrenewed. This is the trap noted when inbuxa's own domains were switched to Automatic on 2026-09-13.
Now a renewal that isn't due returns a new `AcmeRenewal` task due at the certificate's renewal point, exactly as a successful renewal does, and logs it as `RenewBackoff`. The task manager is its only caller. The certificates guide (admin #39) shows this state as *already covered, renews on …*.
The ACME integration suite gains a check: renewing again right after issuance returns one `AcmeRenewal` for that domain, due at the certificate's renewal point.
**Not run yet. Please run it somewhere Pebble can reach the test server.** `automation::automation_tests` fails on the dev laptop *before* the new check, at the first issuance, and it fails identically on unchanged main. ufw drops traffic from the `stalwart-test-acme` docker network (172.21.0.0/16) to the host, so Pebble's TLS-ALPN / HTTP-01 connections to ports 8899/8898 never arrive (confirmed with a container → host probe). To run it locally:
```
sudo ufw allow in on br-e9f716ec2642 to any port 8898:8899 proto tcp
STORE=RocksDb RUST_MIN_STACK=16777216 cargo test -p tests --lib -- automation::automation_tests --exact --include-ignored
```
`cargo check -p common` is clean. CI builds but doesn't run the suite.
When a valid certificate already covered a domain's names (one stored
by hand before the domain was switched to automatic, for instance), the
renewal task ended with NotDue, which the task manager treats as a
permanent failure. Nothing rescheduled it, so the certificate expired
unrenewed. The renewal now returns a new AcmeRenewal task due when the
certificate falls due, the same way a successful renewal does, and logs
it as a backoff.
The ACME integration suite checks that renewing again right after
issuance hands back one AcmeRenewal for that domain, due at the
certificate's renewal point.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
When a valid certificate already covered a domain's names (one stored by hand before the domain was switched to automatic, say),
acme_renewreturnedNotDue. The task manager treats that as a permanent failure, and nothing rescheduled the renewal, so the certificate later expired unrenewed. This is the trap noted when inbuxa's own domains were switched to Automatic on 2026-09-13.Now a renewal that isn't due returns a new
AcmeRenewaltask due at the certificate's renewal point, exactly as a successful renewal does, and logs it asRenewBackoff. The task manager is its only caller. The certificates guide (admin #39) shows this state as already covered, renews on ….The ACME integration suite gains a check: renewing again right after issuance returns one
AcmeRenewalfor that domain, due at the certificate's renewal point.Not run yet. Please run it somewhere Pebble can reach the test server.
automation::automation_testsfails on the dev laptop before the new check, at the first issuance, and it fails identically on unchanged main. ufw drops traffic from thestalwart-test-acmedocker network (172.21.0.0/16) to the host, so Pebble's TLS-ALPN / HTTP-01 connections to ports 8899/8898 never arrive (confirmed with a container → host probe). To run it locally:cargo check -p commonis clean. CI builds but doesn't run the suite.