I assume that by default certbot only checks the expiration date of local certificates against the system clock, it doesn't ping any external resources so it can't be aware that the certificate might have been revoked even though it hasn't expired.
I agree that it would be nice if there was such an option, although I assume that it would increase the server load significantly if certbot connected to letsencrypt's servers at every invocation so maybe that's why they didn't do it.
I think the actual issue here is that the certificates have not been revoked yet. We know that they will be revoked, which is why we have to run with --force-renewal, but there is no process for certbot to know that a certificate, although not revoked, will soon become revoked. I would expect certbot to automatically renew the next time its ran post-revocation.
Check your domain using the linked online tool.
I do get "you didn't renew your certificate" messages on a semi regular basis (domains that have passed out of my control) so I know they have my details.
I hope they add support for that soon.
https://community.letsencrypt.org/t/certbot-1-3-0-release/11...
(only certbot-auto users are likely to get this release immediately)
Was this feature something already planned (albeit presumably not for release today) or was it entirely inspired by this problem? I confess if you'd asked me "What extra features does Certbot need?" I would not have listed "Check OCSP to trigger renewal" though in hindsight it's a good idea.
Those do exist, though I don't personally have access to them. When things are calmer, you might ask bmw or jsha on the Let's Encrypt forum for some more information.
> Was this feature something already planned (albeit presumably not for release today) or was it entirely inspired by this problem?
I wrote (incomplete) code for this feature several years ago -- specifically inspired by the idea that certificates might sometimes be revoked unexpectedly -- but I don't think anyone planned to continue working on it until this problem came around.