When a valid certificate already covered a domain's names (one stored by hand before the domain was switched to automatic, for instance), the renewal task ended with NotDue, which the task manager treats as a permanent failure. Nothing rescheduled it, so the certificate expired unrenewed. The renewal now returns a new AcmeRenewal task due when the certificate falls due, the same way a successful renewal does, and logs it as a backoff. The ACME integration suite checks that renewing again right after issuance hands back one AcmeRenewal for that domain, due at the certificate's renewal point.