# DirectAdmin Certificate Not Renewing: Fix Failed Renewals

Source: https://srvscripts.com/guides/directadmin-certificate-not-renewing/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Since 1.706 DirectAdmin renews certificates itself, once a day, through an embedded ACME client based on lego. When it works it is invisible. When it fails, the symptoms are a browser warning on a customer site or an alert from an external expiry monitor, and the fix depends on which of half a dozen causes is in play. The 1.710 release added a **Provisioning history** page that records every attempt, which turns the investigation from log archaeology into a short read. This guide follows the path we use.

In short: Open Admin Level → Provisioning history (1.710 and later), filter by the domain and read the lego error on the last few attempts: connection refused or timeout means port 80 is unreachable for that name, a CAA error means the record…

**Short answer:** Open Admin Level → Provisioning history (1.710 and later), filter by the domain and read the lego error on the last few attempts: connection refused or timeout means port 80 is unreachable for that name, a CAA error means the record excludes the provider, and an abrupt stop means `acme_disable_after_failures` parked the domain. Fix the cause, re-enable automatic TLS for the domain, then queue `action=tls&value=renew&domain=example.com` in the task queue rather than waiting for the daily run.

## Start with Provisioning history

At Admin Level in Evolution open **Provisioning history** (users see their own domains’ entries on the SSL page). Each row shows the domain, the names requested, the provider, the time and either success or the error string lego returned. Filter by the failing domain and look at the most recent three or four entries. The pattern matters as much as the message: a single failure followed by success was a transient DNS or CA problem; a run of identical failures is a configuration fault; and a run that stops abruptly means the failure counter hit its limit.

That counter is `acme_disable_after_failures`. Once a domain fails that many times in a row, DirectAdmin stops trying, and it stays stopped until someone re-enables automatic TLS for the domain. This is deliberate, to protect the server’s rate-limit budget at the CA, but it means a domain that was disabled two months ago now has an expired certificate and no fresh log entries.

```
da config-get acme_disable_after_failures
```

Re-enable from the user’s SSL page or by toggling the automatic option for the domain, then trigger a run rather than waiting for the daily task:

```
echo "action=tls&value=renew&domain=example.com" >> /usr/local/directadmin/data/task.queue
tail -f /var/log/directadmin/system.log
```

Check the changelog for your build if the queue syntax differs; the TLS actions were documented with 1.706 and refined in later releases.

## Decode the lego message

The error text on the history page comes from lego, and a handful of messages cover most cases.

An authorization error mentioning `connection refused` or `timeout` on the HTTP-01 challenge means the CA could not reach port 80 on this server for that name. Either DNS points elsewhere, Cloudflare or another proxy sits in front and blocks the path, or CSF is dropping the CA’s connections. Confirm with `dig +short example.com A` and compare with the server’s IPs.

`urn:ietf:params:acme:error:caa` means a CAA record at the domain or a parent forbids the provider. The domain’s CAA must include the CA DirectAdmin is using; since 1.707 that may be ZeroSSL rather than Let’s Encrypt, depending on `default_acme_profile` and the order of providers.

`too many certificates already issued` is a CA rate limit, typically hit by a busy reseller who created many subdomains in a day. Wait, or switch that domain to the second provider.

A DNS-01 failure that mentions `_acme-challenge` on a wildcard request usually means the delegation CNAME described in [Wildcard certificates with DNS challenge on DirectAdmin](/guides/directadmin-wildcard-certificate-dns/) is missing or points at a zone this server does not control. 1.708 added detection for that CNAME, and the history entry says so explicitly.

`unauthorized` with a mention of a `.well-known` path returning 404 or 301 means a redirect rule in the site’s `.htaccess` is catching the challenge path. Add an exception before the rewrite rules:

```
RewriteRule ^\.well-known/acme-challenge/ - [L]
```

## Check the wider configuration

If the history is empty for the domain, the daily task never considered it. The most common reason is that the domain never opted in, which shows as `ssl=OFF` in `/usr/local/directadmin/data/users/USER/domains/example.com.conf`. The second is that it is on the manual-certificate allowlist because someone uploaded a certificate once, so the automation is deliberately leaving it alone. The third is a resolver problem: with `acme_use_only_system_resolver` on and a broken local resolver, every pre-check fails before lego is even called, and the log line is in `system.log` rather than the history page.

```
grep -E 'ssl=|ssl_cert' /usr/local/directadmin/data/users/*/domains/example.com.conf
grep -i acme /var/log/directadmin/system.log | tail -20
```

Certificates are renewed at 65 percent of their lifetime from 1.711, so with shorter certificate lifetimes coming into force a domain now renews well before the halfway point of the old 90-day schedule. If the history shows successes but the browser still shows the old certificate, the issue is on the service side rather than the issuance side; see [Services still serving the old certificate after renewal](/guides/directadmin-old-certificate-exim-dovecot/).

## Common pitfall: fixing DNS and expecting an instant retry

After correcting a DNS record, administrators often wait an hour and conclude the fix failed. The daily task runs once, and a domain disabled by the failure counter is not retried at all. Always re-enable the domain and queue a manual run after a fix, and remember that a negative DNS answer may be cached by Unbound or the upstream resolver for the TTL of the SOA’s minimum field.

## Verify

Confirm the certificate on the wire, not only in the panel:

```
openssl s_client -connect example.com:443 -servername example.com /dev/null | openssl x509 -noout -dates -issuer -ext subjectAltName
```

The `notAfter` date should be in the future and the SAN list should contain every name you expected. Then look at the history page again a day later to see the next scheduled pass recorded the domain as healthy. Our [SSL expiry check script](/scripts/ssl-expiry-check/) run weekly across all hosted domains catches the domains that the failure counter has quietly parked before customers do.

## DirectAdmin certificate not renewing at a glance

**Official documentation:** [Let’s Encrypt documentation](https://letsencrypt.org/docs/), [DirectAdmin documentation](https://docs.directadmin.com/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Migrating domains to DirectAdmin’s new ACME TLS system (1.706+) and running the migration task](https://srvscripts.com/guides/directadmin-acme-tls-migration-1-706/) · [Exim, Dovecot or DirectAdmin still serving the old certificate after renewal](https://srvscripts.com/guides/directadmin-old-certificate-exim-dovecot/) · [KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback](https://srvscripts.com/guides/kernelcare-setup-cpanel-directadmin/).

## Frequently asked questions

### Does DirectAdmin retry a failed certificate renewal automatically?

Once a day, until the domain reaches the acme_disable_after_failures limit; after that it is not retried at all until someone re-enables automatic TLS for the domain and queues a run.

### How long before expiry does DirectAdmin renew certificates?

From 1.711 renewal is attempted at 65 percent of the certificate’s lifetime, so a 90-day certificate renews after about 58 days and shorter-lived certificates renew proportionally earlier.

### Can I force a certificate renewal on DirectAdmin without waiting for the daily task?

Yes. Append `action=tls&value=renew&domain=example.com` to /usr/local/directadmin/data/task.queue and watch system.log; the run happens within a minute once dataskq picks it up.
