Junk Drawer Logo Junk Drawer

For all those little papers scattered across your desk

I stand for the Constitution, for due process, and for community that takes care of each other.

Renewing Tailscale-provided Certificates

D. Ben Knoble on 06 Oct 2026 in Blog

A quick note on Tailscale-provided SSL certificates.

Tailscale provides certificates through the ACME protocol with Let’s Encrypt. Their current policy recommends frequent automatic rotation within the 90-day window, and in 2028 we’ll have a 45-day window.

So, one might think to set up a cron job like

%monthly * 0-5 4-6 cd /etc/nginx && /usr/bin/tailscale cert <host>

to trigger a rotation near the beginning of each month. Nice and automatic, and works for the 45-day window, too, right?

Well, the first time my such job ran, I got

Public cert unchanged at <host>.crt
Private key unchanged at <host>.key

What?

It turns out that even after some changes in certificate renewal, Tailscale waits for Let’s Encrypt to say it’s a good window for renewal and then queues a background job to update the cert! Thanks to the Let’s Encrypt community forum for pointing me to that information.

So I’ve now settled on a weekly job:

%weekly * 0-5 /root/renew-cert

that runs a simple script:

#! /bin/sh

cd /etc/nginx || exit 1
/usr/bin/tailscale cert <host>.net >/dev/null 2>&1 || {
  err=$?
  echo 'failed to renew certificate'
  exit $err
}

The output is for my email, since I let cron email me output. (Apparently that’s antiquated now?)


Tags:

Categories: Blog

Load Comments
Previous Next
Back to posts