- Symptom
- Three live properties, including a medical practice, were running on purchased certificates that had to be renewed and reinstalled by hand every year. One was 26 days from expiry, and the vendor's renewal was priced at several times the cost of a new certificate.
- Investigation
- Confirmed the platform had no automatic issuance available, and that the paid certificates were themselves blocking any managed alternative from taking over. Established that the account supported shell access, which made a self-managed ACME client viable.
- Root cause
- The real problem wasn't the expiry date — it was that renewal depended on a human remembering. Any process that fails silently once a year will eventually fail.
- Resolution
- Installed an ACME client at shell level with a scheduled renewal job, issued and deployed certificates for all three domains, and verified the full chain in the browser. Recurring cost eliminated, and renewal no longer depends on anyone noticing.