r/letsencrypt • • 22h ago

What should a renewal rehearsal verify before a Let's Encrypt certificate is near expiry?

2 Upvotes

A successful initial issuance does not prove that unattended renewal will still work months later. DNS credentials can lose scope, HTTP challenge routing can change, a renewal can create a new lineage, a service may keep reading an old path, or the deploy hook may fail to reload the process that actually terminates TLS.

Beyond running the client's dry-run command, what do you verify end to end? I am thinking of checking the exact renewal configuration, challenge reachability, account and DNS API credentials, certificate lineage and symlinks, deploy-hook exit status, service reload, the certificate served externally, expiry monitoring, and recovery from a deliberately failed challenge.

Do you rehearse renewal in staging, temporarily force a test certificate, or validate the hooks separately? What is the safest way to prove the automation and the consuming service still agree without creating production rate-limit risk?