Skip to content

Renewal ​

Let's Encrypt certificates last ~90 days. NitHost renews them for you.

Who can use this page? All site managers should understand renewal; issuance is site manage.

How renewal works ​

  1. certbot container renews on a ~12h loop
  2. HTTP-01 uses the shared webroot; DNS-01 uses stored provider creds
  3. nginx-reloader reloads Nginx with the new cert — zero downtime
  4. Panel expiry reconciler updates expires_at from disk every 12h so the SSL page stays accurate

What you must keep working ​

ChallengeMust remain true
HTTP-01Port 80 open; domain still points here; webroot not firewalled
DNS-01API token valid; zone still on the provider; token not rotated without updating NitHost

Checking status ​

SSL / TLS page:

  • Issued / expires dates
  • Domains covered
  • Errors from last renewal (if surfaced)

If renewal fails ​

  1. Fix DNS / firewall / token (see Troubleshooting)
  2. Trigger renew / reissue from the panel
  3. Contact NitHost support with the domain, expiry date, and exact error.

Expiry email alerts ​

Keep your contact email current. Ask NitHost support which certificate-expiry notifications are available on your service.

Customer documentation · Nusite IT Consulting Limited