CyberPanel SSL Renewals Can Show Success While Serving Expired Certificates
A routine server check revealed that CyberPanel was reporting SSL renewals as successful while OpenLiteSpeed continued serving an outdated or staging certificate. The root cause was that CyberPanel's underlying tool, acme.sh, had been configured to use Let's Encrypt's staging CA instead of the production CA, meaning renewed certificates were not browser-trusted. Because CyberPanel simply reports acme.sh's exit status as success, the mismatch between reported and actual certificate state goes undetected without manual verification using tools like OpenSSL. The fix involved forcing acme.sh back to the production CA, dropping the staging registration, reissuing the certificate, and reloading OpenLiteSpeed. To prevent recurrence, the author developed two shell scripts that bypass CyberPanel's scheduler and handle both routine renewals and broken-certificate recovery independently.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in