Self-Help Article (External)
Intended Audience: IT Staff
Purpose
This article explains how to configure Apache HTTPD to use Certbot-managed certificates and automatically deploy renewed certificates obtained through the CertiNext ACME service.
Requirements
Step-by-Step Procedures
Step 1: Configure Apache HTTPD to Use the Certificate
- Identify the certificate name.
Command:
sudo certbot certificates
- Review the results and identify the certificate name associated with the website.
- Open the HTTPS virtual host configuration file.
Command:
sudo vi /etc/httpd/conf.d/ssl.conf
- Configure Apache HTTPD to use the Certbot-managed certificate files.
Configuration:
SSLCertificateFile /etc/letsencrypt/live/<certificate-name>/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/<certificate-name>/privkey.pem
- Replace <certificate-name> with the certificate name identified in Step 1.
- Save the configuration file.
Notes:
- Always reference the files located in /etc/letsencrypt/live/.
- Do not copy certificates to alternate locations unless required by a specific application.
- Certbot automatically updates these files when certificates are renewed.
Step 2: Validate the Apache Configuration
- Verify the Apache HTTPD configuration syntax.
Command:
sudo apachectl configtest
- Review the results.
- Confirm the following message is displayed:
Syntax OK
- Resolve any reported errors before proceeding.
Step 3: Reload Apache HTTPD
- Reload the Apache HTTPD service.
Command:
sudo systemctl reload httpd
Note: This procedure uses systemctl reload httpd, not systemctl restart httpd. A reload allows Apache to begin using the renewed certificate without disconnecting active users or causing a service outage.
- Verify the Apache HTTPD service is running.
Command:
systemctl status httpd
- Confirm the service status is active (running).
Step 4: Configure Automatic Certificate Deployment (Deploy Hook) Following Renewal
- Create the Certbot deploy hook directory if it does not already exist.
Command:
sudo mkdir -p /etc/letsencrypt/renewal-hooks/deploy
- Create a deployment hook script.
Command:
sudo vi /etc/letsencrypt/renewal-hooks/deploy/reload-httpd.sh
- Add the following content:
#!/bin/bash
systemctl reload httpd
- Save the file.
- Make the script executable.
Command:
sudo chmod 755 /etc/letsencrypt/renewal-hooks/deploy/reload-httpd.sh
Notes:
- The manual reload performed in Step 3 applies the Apache configuration changes made during the initial certificate deployment.
- Certbot automatically runs deployment hook scripts located in /etc/letsencrypt/renewal-hooks/deploy/ after a successful certificate renewal.
- Reloading Apache HTTPD causes the web server to begin using the renewed certificate.
- Existing client connections are not interrupted during a reload operation.
- Future certificate renewals will automatically trigger systemctl reload httpd through this deploy hook, allowing Apache to begin using the renewed certificate without requiring manual intervention
Step 5: Test Automatic Certificate Deployment
- Run a simulated certificate renewal.
Command:
sudo certbot renew --dry-run
- Review the results.
- Confirm the following message is displayed:
Congratulations, all simulated renewals succeeded.
- Verify that no Apache HTTPD errors are reported during the renewal process.
- Resolve any reported errors before relying on automatic certificate deployment in production.
Notes:
- The --dry-run option performs a simulated certificate renewal for testing purposes.
- No new certificate is permanently installed during the test.
- Successful completion confirms that automatic certificate renewal and deployment are expected to function correctly when an actual renewal occurs.
Automatic Certificate Deployment Workflow for a Website
Certbot-renew.timer runs
↓
Certbot checks certificate expiration
↓
Certificate eligible for renewal?
↓
No → Renewal check completes
↓
Yes
↓
Certificate is renewed
↓
Certbot updates certificate files in
/etc/letsencrypt/live/<certificate-name>/
↓
Certbot executes deploy hook
(reload-httpd.sh)
↓
systemctl reload httpd
↓
Apache reloads configuration
↓
Apache reads the updated certificate files
↓
Website serves the renewed certificate
Notes:
- The timing of certificate renewal and any associated Apache HTTPD reload is controlled by the certbot-renew.timer schedule.
- Routine renewal checks that do not result in a certificate renewal do not trigger an Apache HTTPD reload.
Additional Information
- View Certbot Deployment Hooks
Command:
ls -l /etc/letsencrypt/renewal-hooks/deploy/
- Manually Reload Apache HTTPD
Command:
sudo systemctl reload httpd
- View Apache HTTPD Service Logs
Command:
sudo journalctl -u httpd