Skip to content

Let's Encrypt certificates for new domains take too long to obtain

Summary

Found while investigating #35934 (closed)

Steps to reproduce

Very quickly execute these steps

  1. Add new domain
  2. verify it
  3. enable Let's Encrypt ssl

What is the current bug behavior?

It will take up to 24 hours to obtain certificate

What is the expected correct behavior?

The certificate is working under 30 minutes

Output of checks

This bug happens on GitLab.com

Possible fixes

  1. Remove acme_order if they are in invalid state or
  2. Manually reduce expiration time to 15 minutes

cc @ogolowinski @jmeshell @jhampton