From: "Dan Napier" Received: from [192.168.100.201] (HELO mail.2rosenthals.com) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTP id 2580453 for ecs-isp@2rosenthals.com; Mon, 25 May 2026 12:47:40 -0400 Received: from [192.168.200.201] (port=43137 helo=mail2.2rosenthals.com) by mail.2rosenthals.com with esmtp (Exim 4.98.2) (envelope-from ) id 1wRYSg-000000005JR-1FS7 for ecs-isp@2rosenthals.com; Mon, 25 May 2026 12:47:31 -0400 Received: from kaliss.dnacih.com ([47.180.217.131]:42784) by mail2.2rosenthals.com with esmtp (Exim 4.98.2) (envelope-from ) id 1wRYSa-000000001mt-23xf for ecs-isp@2rosenthals.com; Mon, 25 May 2026 12:47:26 -0400 Received: from scotty.dnacih.com (scotty.dnacih.com [64.60.60.125]) by kaliss.dnacih.com with ESMTP id cTAc1oFWLvIdJtmv for ; Mon, 25 May 2026 09:47:16 -0700 (PDT) X-SASI-Hits: BODYTEXTH_SIZE_10000_LESS 0.000000, BODYTEXTH_SIZE_3000_MORE 0.000000, BODY_SIZE_10000_PLUS 0.000000, DKIM_ALIGNS 0.000000, DKIM_SIGNATURE 0.000000, HREF_LABEL_TEXT_NO_URI 0.000000, HREF_LABEL_TEXT_ONLY 0.000000, HTML_50_70 0.100000, HTML_NO_HTTP 0.100000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSG_THREAD 0.000000, MSG_THREAD_SOLO 0.000000, NO_URI_HTTPS 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SENDER_NO_AUTH 0.000000, SUSP_DH_NEG 0.000000, TEXT_DIRECTION 0.000000, TO_IN_SUBJECT 0.500000, USER_AGENT 0.000000, __ANY_URI 0.000000, __ATTACH_CTE_QUOTED_PRINTABLE 0.000000, __BANNER_TRUSTED_SENDER 0.000000, __BODY_TEXT_X4 0.000000, __BODY_VOICEMAIL 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CP_NOT_1 0.000000, __CP_URI_IN_BODY 0.000000, __CT 0.000000, __CTYPE_HAS_BOUNDARY 0.000000, __CTYPE_MULTIPART 0.000000, __CTYPE_MULTIPART_ALT 0.000000, __DKIM_ALIGNS_1 0.000000, __DKIM_ALIGNS_2 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FRAUD_INTRO 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_HTML 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HELO_LOCALHOST 0.000000, __HELO_LOCALHOST2 0.000000, __HIGHBIT_ASCII_MIX 0.000000, __HREF_LABEL_TEXT 0.000000, __HTML_AHREF_TAG 0.000000, __HTML_ATTR_DIR 0.000000, __HTML_BAD_END 0.000000, __HTML_HREF_TAG_X2 0.000000, __HTML_TAG_DIV 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __MAIL_CHAIN 0.000000, __MIME_HTML 0.000000, __MIME_TEXT_H 0.000000, __MIME_TEXT_H1 0.000000, __MIME_TEXT_H2 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_TEXT_P2 0.000000, __MIME_VERSION 0.000000, __MULTIPLE_URI_TEXT 0.000000, __PART_TYPE_HTML 0.000000, __PHISH_PHRASE1_A 0.000000, __PHISH_SPEAR_GREETING 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __SL_HEAVY 0.000000, __STYLE_RATWARE_NEG 0.000000, __STYLE_TAG 0.000000, __STYLE_TAGS_ATTACHED 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TAG_EXISTS_BODY 0.000000, __TAG_EXISTS_HEAD 0.000000, __TAG_EXISTS_HTML 0.000000, __TO_IN_SUBJECT 0.000000, __TO_IN_SUBJECT2 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __UNSUBSCRIBE_1 0.000000, __URI_IN_BODY 0.000000, __URI_MAILTO 0.000000, __URI_NOT_IMG 0.000000, __URI_NO_PATH 0.000000, __URI_NS 0.000000, __URI_WITHOUT_PATH 0.000000, __USER_AGENT 0.000000, __X_VIRUS_SCANNED 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2026.5.25.155719 X-SASI-Hits: BODYTEXTH_SIZE_10000_LESS 0.000000, BODYTEXTH_SIZE_3000_MORE 0.000000, BODY_SIZE_10000_PLUS 0.000000, DKIM_ALIGNS 0.000000, DKIM_SIGNATURE 0.000000, HREF_LABEL_TEXT_NO_URI 0.000000, HREF_LABEL_TEXT_ONLY 0.000000, HTML_50_70 0.100000, HTML_NO_HTTP 0.100000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSG_THREAD 0.000000, MSG_THREAD_SOLO 0.000000, NO_URI_HTTPS 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SENDER_NO_AUTH 0.000000, SUSP_DH_NEG 0.000000, TEXT_DIRECTION 0.000000, TO_IN_SUBJECT 0.500000, USER_AGENT 0.000000, __ANY_URI 0.000000, __ATTACH_CTE_QUOTED_PRINTABLE 0.000000, __BANNER_TRUSTED_SENDER 0.000000, __BODY_TEXT_X4 0.000000, __BODY_VOICEMAIL 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CP_NOT_1 0.000000, __CP_URI_IN_BODY 0.000000, __CT 0.000000, __CTYPE_HAS_BOUNDARY 0.000000, __CTYPE_MULTIPART 0.000000, __CTYPE_MULTIPART_ALT 0.000000, __DKIM_ALIGNS_1 0.000000, __DKIM_ALIGNS_2 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FRAUD_INTRO 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_HTML 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HELO_LOCALHOST 0.000000, __HELO_LOCALHOST2 0.000000, __HIGHBIT_ASCII_MIX 0.000000, __HREF_LABEL_TEXT 0.000000, __HTML_AHREF_TAG 0.000000, __HTML_ATTR_DIR 0.000000, __HTML_BAD_END 0.000000, __HTML_HREF_TAG_X2 0.000000, __HTML_TAG_DIV 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __MAIL_CHAIN 0.000000, __MIME_HTML 0.000000, __MIME_TEXT_H 0.000000, __MIME_TEXT_H1 0.000000, __MIME_TEXT_H2 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_TEXT_P2 0.000000, __MIME_VERSION 0.000000, __MULTIPLE_URI_TEXT 0.000000, __PART_TYPE_HTML 0.000000, __PHISH_PHRASE1_A 0.000000, __PHISH_SPEAR_GREETING 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __SL_HEAVY 0.000000, __STYLE_RATWARE_NEG 0.000000, __STYLE_TAG 0.000000, __STYLE_TAGS_ATTACHED 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TAG_EXISTS_BODY 0.000000, __TAG_EXISTS_HEAD 0.000000, __TAG_EXISTS_HTML 0.000000, __TO_IN_SUBJECT 0.000000, __TO_IN_SUBJECT2 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __UNSUBSCRIBE_1 0.000000, __URI_IN_BODY 0.000000, __URI_MAILTO 0.000000, __URI_NOT_IMG 0.000000, __URI_NO_PATH 0.000000, __URI_NS 0.000000, __URI_WITHOUT_PATH 0.000000, __USER_AGENT 0.000000, __X_VIRUS_SCANNED 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2026.5.25.155719 X-Barracuda-Envelope-From: dan@cihcsp.com X-Barracuda-Effective-Source-IP: scotty.dnacih.com[64.60.60.125] X-Barracuda-Apparent-Source-IP: 64.60.60.125 X-ASG-Whitelist: Client Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id D6E266C0507 for ; Mon, 25 May 2026 09:47:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cihcsp.com; s=dkim; t=1779727634; h=from:reply-to:subject:date:message-id:to:mime-version:content-type: in-reply-to:references; bh=V3zxrutMV41JNJ6siJ9K/GNg017yRm9K0xlW9L6o79s=; b=Bc7VWgb8M3TaoQZqi5h9PRRPt6hte8kijXM+OeCxFSPBYCHwcXlx9nguM/hXrlCOmCt3fs m7k4HB9fIeg4HDHv6gaY5DY7MJ/bXDDjWSOyQrnSo6Zjit01q89z4yHJNKpLO9nqBe6fPX eRpDEybTGbYTr4NvZlALpn3I1BY/+0o1FKXXK8MHpTd9W2jFyNd/ctDaQydAartz965I4p G4BT3op6zCNXuZQkrUFDjxMu9V8JVKdX+8PFadJg5jO9rqOmGikcVobetMMNQ9Zt94v7fE ZwSbXWgHwBzvbwNDRxSxXFxRpcB25fHqCwR4COqx091oNgsLXxLLFdFxBJZoPQ== To: "eCS ISP Mailing List" Subject: Re: [eCS-ISP] Re[2]: [eCS-ISP] Re[2]: [eCS-ISP] SSL cert lifetime Date: Mon, 25 May 2026 16:47:12 +0000 X-ASG-Orig-Subj: Re: [eCS-ISP] Re[2]: [eCS-ISP] Re[2]: [eCS-ISP] SSL cert lifetime Message-Id: In-Reply-To: References: Reply-To: "Dan Napier" User-Agent: eMClient/10.4.0.0 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="------=_MBBA0FE609-7D93-46A1-BE6F-BA2FEE4E50DD" X-Last-TLS-Session-Version: TLSv1.3 X-Barracuda-Connect: scotty.dnacih.com[64.60.60.125] X-Barracuda-Start-Time: 1779727636 X-Barracuda-URL: https://47.180.217.131:443/cgi-mod/mark.cgi X-Barracuda-BRTS-Status: 0 X-Virus-Scanned: by bsmtpd at dnacih.com X-Barracuda-Scan-Msg-Size: 12924 X-ASG-Debug-ID: 1779727636-1013760a8b94830001-4YkuuC --------=_MBBA0FE609-7D93-46A1-BE6F-BA2FEE4E50DD Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: quoted-printable Guys, As a lifelong Safety and Security person, I have often seen what can=20 only be described as less than optimal soulutons to past system=20 failures. Or DAS. Somebody builds a wall that is ten feet high,=20 another comes along with an eleven foot ladder. Or somebody digs a hole=20 under the wall. At a recent criminal investigation during a warranted=20 search, I observed the educated police officer open a tool proof thirty=20 hour safe in about 45 seconds. So changing the combination daily would=20 not have solved that problem! "The best laid plans of mice and men gang=20 aft agley" Respectfully Submitted Dan Napier ------ Original Message ------ From "Dan Napier" To "eCS ISP Mailing List" Date 5/17/2026 7:03:17 PM Subject [eCS-ISP] Re[2]: [eCS-ISP] Re[2]: [eCS-ISP] SSL cert lifetime >Peter, >Yes I think that linux tries much more often. But I have not found that=20 >Steve=E2=80=99s script needs to run more than once. I guess I am just luck= y. >Cron on the first tenth twentieth and twenty ninth. In the middle of=20 >the night on the west coast. But I am still testing. More news in=20 >December. >Dan > >------ Original Message ------ >From "Peter Moylan" >To "eCS ISP Mailing List" >Date 5/17/2026 17:58:41 >Subject Re: [eCS-ISP] Re[2]: [eCS-ISP] SSL cert lifetime > >>On 18/05/26 03:08, Dan Napier wrote: >> >>>Buenso Dai, Chaio, Good day, Well, I am running LE. The mirrored >>>servers problem can be solved. You need to be in control of both your >>>Apache servers and your DNS servers. It is a security issue so I >>>would not dream of discussing that on a public platform. It can be >>>accomplished. For a single OS2 apache server with no control to the >>>DNS you can use cron to run steven's script on a few days of the >>>month. If LE fails to update nothing happens, if it updates it >>>updates! I forgot to update and decided to try that so far so good. >> >>Does you "a few days of the month" mean that you are suggesting getting >>a new certificate a lot more often than required? I hadn't thought of tha= t. >> >>I'm not using cron to schedule this. Instead, I'm using a feature of >>DragText that puts a "Schedule" page into the Properties of every >>program object. At present I run my update script once every 80 days. >> >>Let's Encrypt has two main drawbacks: >>1. The short expiry time (90 days). >>2. The fact that an update attempt often fails (busy server?) so that >>the job has to be repeated manually. >> >>I keep meaning to write a higher-level script that will check for an >>update failure and repeat the attempt an hour or two later. The best >>checking method is not yet obvious to me. Parse the log file, or look at >>the "last written" date of the certificate file? Probably the latter is >>easier. >> >>>Is there a utility that will start to run a script every 47 days? Or >>>be smart enuf to remember when it last ran and run 47 days later? >> >>DragText can do that, but I would have thought that cron can also do it. >> >>-- Peter Moylan peter@pmoylan.org >>http://www.pmoylan.org >> >>=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-= =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D >>This message is sent to you because you are subscribed to >> the mailing list . >>To unsubscribe, E-mail to: >>To switch to the DIGEST mode, E-mail to >>To switch to the INDEX mode, E-mail to >>Send administrative queries to >>To subscribe (new addresses), E-mail to: and = reply to the confirmation email. >>Web archives are publicly available at: http://lists.2rosenthals.com >> >>This list is hosted by Rosenthal & Rosenthal, LLC >>P.O. Box 281, Deer Park, NY 11729-0281. Non- >>electronic communications related to content >>contained in these messages should be directed >>to the above address. (CAN-SPAM Act of 2003) >> >>=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-= =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D >> --------=_MBBA0FE609-7D93-46A1-BE6F-BA2FEE4E50DD Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable
Guys,

As a lifelong Safety and Securi= ty person, I have often seen what can only be described as less than optima= l soulutons to past system failures.=C2=A0 Or DAS.=C2=A0 Somebody builds a= wall that is ten feet high, another comes along with an eleven foot ladder.= =C2=A0 Or somebody digs a hole under the wall.=C2=A0 At a recent criminal i= nvestigation=C2=A0during a warranted search,=C2=A0I observed=C2=A0 the educ= ated police officer open a tool proof thirty hour safe in about 45 seconds.= =C2=A0 So changing the combination daily would not have solved that problem= !=C2=A0 "The best laid plans of mice and men gang=C2=A0aft=C2=A0agley"=C2= =A0=C2=A0

Respectfully Submit= ted

Dan Napier<= /div>


------ Original Message ------
From "Dan Napier" <ecs-i= sp@2rosenthals.com>
To "eCS ISP Mailing List" <ecs-isp@2rosenthals.com>
Date 5/17/2026 7:03:17 PM
Subject [eCS-ISP] Re[2]: [eCS-ISP] Re[2]: [eCS-ISP] SSL cert lifetime<= /div>

Peter,
Yes I think that linux tries much more o= ften. But I have not found that Steve=E2=80=99s script needs to run more th= an once. I guess I am just lucky.=C2=A0
Cron on the= first tenth twentieth and twenty ninth. In the middle of the night on the w= est coast. But I am still testing. More news in December.=C2=A0
Dan

------ Original Message ------
From "Peter Moylan" <ecs= -isp@2rosenthals.com>
To "eCS ISP Mailing List" <ecs-isp@2rosenthals.com>
Date 5/17/2026 17:58:41
Subject Re: [eCS-ISP] Re[2]: [eCS-ISP] SSL cert lifetime

On 18/05/26 03:08, Dan Napier wrote:
=C2=A0
Buenso Dai, Chaio, Good day, Well, I am running= LE. The mirrored
servers problem can be solved. You need to be in= control of both your
Apache servers and your DNS servers. It is a secu= rity issue so I
would not dream of discussing that on a public pl= atform. It can be
accomplished. For a single OS2 apache server wit= h no control to the
DNS you can use cron to run steven's script on a= few days of the
month. If LE fails to update nothing happens, i= f it updates it
updates! I forgot to update and decided to try t= hat so far so good.
=C2=A0
Does you "a few days of the month" mean that you= are suggesting getting
a new certificate a lot more often than required? = I hadn't thought of that.
=C2=A0
I'm not using cron to schedule this. Instead, I'm = using a feature of
DragText that puts a "Schedule" page into the Pro= perties of every
program object. At present I run my update script = once every 80 days.
=C2=A0
Let's Encrypt has two main drawbacks:
1. The short expiry time (90 days).
2. The fact that an update attempt often fails (b= usy server?) so that
the job has to be repeated manually.
=C2=A0
I keep meaning to write a higher-level script tha= t will check for an
update failure and repeat the attempt an hour or= two later. The best
checking method is not yet obvious to me. Parse t= he log file, or look at
the "last written" date of the certificate file?= Probably the latter is
easier.
=C2=A0
Is there a utility that will start to run a scrip= t every 47 days? Or
be smart enuf to remember when it last ran and ru= n 47 days later?
=C2=A0
DragText can do that, but I would have thought th= at cron can also do it.
=C2=A0
-- Peter Moylan peter@pmoylan.org
=C2=A0
=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-= =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D
This message is sent to you because you are subsc= ribed to
the mailing list <ecs-isp@2rosenthals.com>.
To unsubscribe, E-mail to: <ecs-isp-off@2rosenthals.com>
To switch to the DIGEST mode, E-mail to <ecs-isp-digest@2rosenthals.com= >
To switch to the INDEX mode, E-mail to <ecs-isp-index@2rosenthals.com>
To subscribe (new addresses), E-mail to: <ecs-isp-on@2rosenthals.com>= ; and reply to the confirmation email.
Web archives are publicly available at: http://lists.2rosenthals.com
=C2=A0
This list is hosted by Rosenthal & Rosenthal, = LLC
P.O. Box 281, Deer Park, NY 11729-0281. Non-
electronic communications related to content
contained in these messages should be directed
to the above address. (CAN-SPAM Act of 2003)
=C2=A0
=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-= =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D
=C2=A0
--------=_MBBA0FE609-7D93-46A1-BE6F-BA2FEE4E50DD--