Self-Help Article (External)
Intended Audience: IT Staff
Purpose
This article explains how to configure Certbot on a Linux web server to request, install, and automatically renew certificates using the CertiNext ACME service.
Requirements
- Certificate
- Valid DNS records exist for all certificate hostnames (FQDNs) and may resolve to either internal or external IP addresses, as appropriate for the service being secured.
- CertiNext
- The certificate hostname (FQDN) must be within the okstate.edu domain which is validated within CertiNext.
- A valid CertiNext ACME API Credential is required.
- If an ACME API Credential has not been issued, submit a Request CertiNext ACME API Credential.
- Renewal notifications will be sent to the email address associated with the CertiNext ACME API Credential.
- Server
- Red Hat Enterprise Linux (RHEL) 8 or later.
- Administrative (root or sudo) access.
- A web application or service requiring a TLS certificate.
- Server network connectivity to https://acme-us.certinext.io/v1/directory
- For Apache HTTPD deployments:
- Apache HTTPD installed.
- The mod_ssl package installed and enabled.
Step-by-Step Procedures
Step 1: Install Certbot
- Install Certbot using DNF.
Command:
sudo dnf install certbot -y
Note: Apache HTTPD servers require the mod_ssl package to support TLS/SSL connections.
rpm -q mod_ssl
- Verify the installation and confirm that Certbot returns a version number.
Command:
certbot --version
- Verify EAB support is available.
Command:
certbot --help all | grep eab
Expected output should display:
--eab-kid
--eab-hmac-key
- If the EAB options are not displayed, update Certbot to a newer supported version before proceeding.
Step 2: Verify DNS Resolution
- Verify that the hostname resolves to the correct IP address.
Command:
dig website.okstate.edu
-
Review the results and confirm that the returned IP address matches the web server hosting the website.
Step 3: Request the CertiNext Certificate
Step 4: Verify Certificate Creation
- Verify that the certificate was successfully issued.
Command:
sudo certbot certificates
- Review the results and confirm that the requested hostname appears in the certificate list.
- Confirm the certificate expiration date is displayed and reflects the expected validity period.
Example Output:
Certificate Name: website.okstate.edu
Domains: website.okstate.edu www.website.okstate.edu
Expiry Date: 2026-11-01
- If the certificate is not listed, review the Certbot output from Step 3 and resolve any reported errors before proceeding.
Step 5: Verify Renewal Configuration
- Review the Certbot renewal configuration file:
Command:
sudo cat /etc/letsencrypt/renewal/<hostname>.conf

- Verify the following entry is present:
server = https://acme-us.certinext.io/v1/directory
Step 6.5 (Optional): Configure a Custom Renewal Schedule
- Create a systemd override for the Certbot renewal timer.
Command:
sudo systemctl edit certbot-renew.timer
- Add a custom OnCalendar schedule.
Example:
[Timer]
OnCalendar=
OnCalendar=Sun *-*-* 02:00:00
- Save the file.
- Reload the systemd configuration.
Command:
sudo systemctl daemon-reload
- Restart the Certbot renewal timer.
Command:
sudo systemctl restart certbot-renew.timer
- Verify the updated renewal schedule.
Command:
systemctl list-timers certbot-renew.timer
- Confirm that the timer is scheduled to run at the expected time.
Notes:
- The example schedule shown above runs the renewal timer every Sunday at 2:00 AM. Modify the OnCalendar value as needed to align with local maintenance windows.
- If automatic certificate deployment is configured, deployment actions such as a web server reload or Tomcat restart occur during the scheduled timer execution window.
- Routine renewal checks that do not result in a certificate renewal do not trigger deployment actions.
Step 7: Test Certificate Renewal
- Run a simulated renewal.
Command:
sudo certbot renew --dry-run
- Review the results.
Expected Output:
Congratulations, all simulated renewals succeeded.
- Resolve any reported errors before placing the certificate into production.
Additional Information
- Locate Certificate Files
- Verify the certificate directory exists.
Path:
/etc/letsencrypt/live/website.okstate.edu/
- Verify that the certificate files exist.
Command:
ls -l /etc/letsencrypt/live/website.okstate.edu/
- Confirm the following files are present:
cert.pem
chain.pem
fullchain.pem
privkey.pem
- Verify Certificate Installation
- Review the certificate expiration date.
Command:
openssl x509 \
-in /etc/letsencrypt/live/website.okstate.edu/cert.pem \
-noout -dates
- Verify HTTPS connectivity.
Command:
curl -Iv https://website.okstate.edu
- Confirm:
- The certificate is trusted.
- The hostname is correct.
- The expiration date is correct.
- No certificate warnings are reported.
- Verify the website loads successfully in a web browser.