# Wowza seems to stop working over https prior to Letsencrypt expiring

**URL:** https://community.wowza.com/t/wowza-seems-to-stop-working-over-https-prior-to-letsencrypt-expiring/91940
**Category:** Wowza Streaming Engine
**Created:** [September 17, 2020, 2:20pm UTC](https://community.wowza.com/t/wowza-seems-to-stop-working-over-https-prior-to-letsencrypt-expiring/91940 "2020-09-17T14:20:40Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Elie\_Obeid](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/elie_obeid/32/463_2.png) [@Elie\_Obeid](https://community.wowza.com/u/Elie_Obeid)
#### Post date: [September 17, 2020, 2:20pm UTC](https://community.wowza.com/t/wowza-seems-to-stop-working-over-https-prior-to-letsencrypt-expiring/91940/1 "2020-09-17T14:20:41Z")

</div>

We have a centos 7 LAMP server and two other centos 7 Wowza 4.8.0 connected by Wowza load balancer. All the servers have the correct Linux date. All the servers have the same let’s encrypt certificate which expires today 17/9/2020.

All the servers are offline and so the SSL has to be renewed manually every 3 months via the DNS verification method. Basically I generate a wildcard certificate on my PC, upload it to the Wowza server, [use this tool](https://github.com/robymus/wowza-letsencrypt-converter), And run this command

`/usr/local/WowzaStreamingEngine/java/bin/java -jar /usr/bin/wowza-letsencrypt-converter-0.2.jar /usr/local/WowzaStreamingEngine/conf/ssl/ /etc/letsencrypt/live/ && systemctl restart WowzaStreamingEngine`

Today I was renewing the certificates, the certificate was working fine on the LAMP server, but was expired on both Wowza servers, chrome tells me that the certificate will expire tomorrow but if you try to watch something over https, it won’t play and the developer console will say certificate invalid, if you try accessing the Wowza manager, it will say the same.

I don’t know for how long it’s been like that, I don’t check the servers on a daily basis, maybe a week, no clue. Is there a reason for Wowza to mark the certificate as invalid before the expiration date? If so can we fix it? and how long before the actual expiration date does the certificate expires? So we can take that into account.

---

<div class="post-metadata">

### Author: ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)
#### Post date: [September 17, 2020, 3:08pm UTC](https://community.wowza.com/t/wowza-seems-to-stop-working-over-https-prior-to-letsencrypt-expiring/91940/2 "2020-09-17T15:08:20Z")

</div>

Let me check with tech support on this for you

---

<div class="post-metadata">

### Author: ![Elie\_Obeid](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/elie_obeid/32/463_2.png) [@Elie\_Obeid](https://community.wowza.com/u/Elie_Obeid)
#### Post date: [September 17, 2020, 3:40pm UTC](https://community.wowza.com/t/wowza-seems-to-stop-working-over-https-prior-to-letsencrypt-expiring/91940/3 "2020-09-17T15:40:46Z")

</div>

Thank you so much, please ask them about this too

> [@DRM - loadbalancer: do the keys have to be on both servers?](http://community.wowza.com/t/drm-loadbalancer-do-the-keys-have-to-be-on-both-servers/91937):
>
> [Wowza drm](https://www.wowza.com/docs/how-to-secure-apple-hls-streaming-using-drm-encryption) I’m currently placing the keys in the [installation-dir]keys/ folder Our client have 2 streaming engines and a wowza load balancer, should the keys folder be created on both servers? should be a shared one? or if it exists on one server, the other server will detect it?

---

<div class="post-metadata">

### Author: ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)
#### Post date: [September 17, 2020, 3:59pm UTC](https://community.wowza.com/t/wowza-seems-to-stop-working-over-https-prior-to-letsencrypt-expiring/91940/4 "2020-09-17T15:59:58Z")

</div>

I responded in the other post for this so we can mark it as accepted solution for that question when people search. 🙂

---

<div class="post-metadata">

### Author: ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)
#### Post date: [September 17, 2020, 4:01pm UTC](https://community.wowza.com/t/wowza-seems-to-stop-working-over-https-prior-to-letsencrypt-expiring/91940/5 "2020-09-17T16:01:45Z")

</div>

For this question @Elie_Obeid, tech support wants to review your certs in a ticket. They need a better understanding of this behavior to see what we may need to do to improve upon the messaging around cert expirations specific to Let’s Encrypt vs our Streamlock. I know we’re trying to make some automated changes and we are currently testing this so a ticket to help with this would be much appreciated.

---

<div class="post-metadata">

### Author: ![Elie\_Obeid](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/elie_obeid/32/463_2.png) [@Elie\_Obeid](https://community.wowza.com/u/Elie_Obeid)
#### Post date: [September 17, 2020, 4:28pm UTC](https://community.wowza.com/t/wowza-seems-to-stop-working-over-https-prior-to-letsencrypt-expiring/91940/6 "2020-09-17T16:28:02Z")

</div>

Sure, I can provide them with new certificates that are valid until 16/9/2020, I can’t provide the old certificates because I don’t have them, they got deleted when applying the new ones.
