so if you have a new certificate it is valid vor 89.something days, you could do a: openssl x509 -in file.crt -checkend 7689600 -noout > /dev/null && /usr/bin/systemctl reload dovecot