Certificates - CertiNext - How to Configure Certificate Renewal on Linux Web Server Using Certbot

Summary

This article explains how to configure Certbot on a Linux web server to request, install, and automatically renew certificates using the CertiNext ACME service.

Body

Self-Help Article (External)

Purpose

This article explains how to configure Certbot on a Linux web server to request, install, and automatically renew certificates using the CertiNext ACME service.

Requirements

Step-by-Step Procedures

Step 1: Install Certbot

  1. Install Certbot using DNF.
    Command:

    sudo dnf install certbot -y

    Note: Apache HTTPD servers require the mod_ssl package to support TLS/SSL connections.
    rpm -q mod_ssl

  2. Verify the installation and confirm that Certbot returns a version number.
    Command:

    certbot --versionUploaded Image (Thumbnail)
  3. Verify EAB support is available​.
    Command:

    certbot --help all | grep eab
    Expected output should display:
    --eab-kid
    --eab-hmac-key
  4. If the EAB options are not displayed, update Certbot to a newer supported version before proceeding.
Step 2: Verify DNS Resolution

  1. Verify that the hostname resolves to the correct IP address.
    Command:

    dig website.okstate.edu
  2. Review the results and confirm that the returned IP address matches the web server hosting the website.
Step 3: Request the CertiNext Certificate
  1. Request a CertiNext ACME-managed certificate for the website.
  2. Replace YOUR_KEY_ID and YOUR_MAC_KEY with the values provided in your CertiNext ACME API Credential.
  3. Request the certificate for a single hostname.
    Command:

    sudo certbot certonly \
    --standalone \

    --server https://acme-us.certinext.io/v1/directory \
    --eab-kid YOUR_KEY_ID \
    --eab-hmac-key YOUR_MAC_KEY \
    -d website.okstate.edu

    Notes: 
    - The certificate validation method may vary depending on the web application or web server hosting the site.
    - The --standalone option temporarily runs its own web server to complete the ACME challenge and does not use the Apache configuration.

    - For environments where --standalone is not suitable, the --apache or --webroot validation methods may be used instead.
    - Validate the appropriate Certbot validation method for your environment before implementation.
  4. To include additional hostnames in the certificate, specify additional -d parameters.
    Command:

    sudo certbot certonly \
    --standalone \

    --server https://acme-us.certinext.io/v1/directory \
    --eab-kid YOUR_KEY_ID \
    --eab-hmac-key YOUR_MAC_KEY \
    -d website.okstate.edu \
    -d www.website.okstate.edu
  5. When prompted for email address for urgent renewal and security notices
    Example: Entered email addressUploaded Image (Thumbnail)
  6. When prompted for Do you agree with the terms of service, select the appropriate option.
    Example: Entered YUploaded Image (Thumbnail)
  7. When prompted for share your email address with Electronic Frontier Foundation, select the appropriate option.
    Example: Entered NUploaded Image (Thumbnail)
  8. If the certificate request is successful, Certbot will:
    1. Register an ACME account with CertiNext.
    2. Validate ownership of the hostname.
    3. Request the certificate.
    4. Store the certificate on the server.

 

Step 4: Verify Certificate Creation
  1. Verify that the certificate was successfully issued.
    Command:

    sudo certbot certificates
  2. Review the results and confirm that the requested hostname appears in the certificate list.
  3. Confirm the certificate expiration date is displayed and reflects the expected validity period.
    Example Output:
    Certificate Name: website.okstate.edu
    Domains: website.okstate.edu www.website.okstate.edu
    Expiry Date: 2026-11-01
  4. If the certificate is not listed, review the Certbot output from Step 3 and resolve any reported errors before proceeding.
Step 5: Verify Renewal Configuration
  1. Review the Certbot renewal configuration file:
    Command:
    sudo cat /etc/letsencrypt/renewal/<hostname>.conf

    Uploaded Image (Thumbnail)
  2. Verify the following entry is present:
    server = https://acme-us.certinext.io/v1/directory
Step 6: Verify Renewal Timer
  1. Verify that the Certbot renewal timer is installed and active.
    Command:
    systemctl status certbot-renew.timer
    Uploaded Image (Thumbnail)
  2. Enable the timer if it is not running.
    Command:
    sudo systemctl enable --now certbot-renew.timer
    Uploaded Image (Thumbnail)
  3. Verify the renewal schedule.
    Command:
    systemctl list-timers | grep certbot​​Uploaded Image (Thumbnail)
  4. Confirm that the Certbot timer is active and scheduled to run automatically.

    Notes:
    - On RHEL 8.x and 9.x systems, Certbot typically uses a systemd timer for automatic certificate renewal. A separate cron job is generally not required.
    - The certificate renewal schedule is controlled by the certbot-renew.timer systemd timer. Administrators can review the configured schedule using:

    systemctl list-timers certbot-renew.timer 
    or 
    systemctl cat certbot-renew.timer
    - When the timer runs, Certbot automatically checks managed certificates and renews only certificates that are approaching expiration.
    - After a successful renewal, Certbot automatically executes any configured deployment hooks to allow the web server or application to begin using the renewed certificate.
    - Renewal status and failures can be reviewed through Certbot logs and systemd journal entries.
    - Additional configuration may be required if email notification for renewal failures is desired
Step 6.5 (Optional): Configure a Custom Renewal Schedule
  1. Create a systemd override for the Certbot renewal timer. 
    Command:

    sudo systemctl edit certbot-renew.timer
  2. Add a custom OnCalendar schedule. 
    Example:

    [Timer]
    OnCalendar=
    OnCalendar=Sun *-*-* 02:00:00
  3. Save the file.
  4. Reload the systemd configuration. 
    Command:

    sudo systemctl daemon-reload
  5. Restart the Certbot renewal timer. 
    Command:

    sudo systemctl restart certbot-renew.timer
  6. Verify the updated renewal schedule. 
    Command:

    systemctl list-timers certbot-renew.timer
  7. Confirm that the timer is scheduled to run at the expected time.

    Notes:
    - The example schedule shown above runs the renewal timer every Sunday at 2:00 AM. Modify the OnCalendar value as needed to align with local maintenance windows.
    - If automatic certificate deployment is configured, deployment actions such as a web server reload or Tomcat restart occur during the scheduled timer execution window.
    - Routine renewal checks that do not result in a certificate renewal do not trigger deployment actions.

Step 7:  Test Certificate Renewal
  1. Run a simulated renewal.
    Command:

    sudo certbot renew --dry-run
  2. Review the results.
    Expected Output:

    Congratulations, all simulated renewals succeeded.
  3. Resolve any reported errors before placing the certificate into production.
Step 8: Configure Automatic Certificate Deployment for the Website
  1. Configure the web server or application to automatically use certificates managed by Certbot. After a successful certificate renewal, the web service may require a reload, restart, or deployment hook to begin using the updated certificate.
  2. Follow the appropriate platform-specific procedure:
    1. Apache HTTPD: Refer to Certificates - CertiNext - How to Configure Automatic Certificate Deployment for Apache HTTPD Using Certbot
    2. Apache Tomcat: Refer to Certificates - CertiNext - How to Configure Automatic Certificate Deployment for Apache Tomcat Using Certbot
  3. After completing the applicable deployment procedure, verify that the website is presenting the expected certificate and that automatic renewal testing succeeds
Additional Information
  1. Locate Certificate Files
    1. Verify the certificate directory exists.
      Path:
      /etc/letsencrypt/live/website.okstate.edu/
    2. Verify that the certificate files exist.
      Command:
      ls -l /etc/letsencrypt/live/website.okstate.edu/
    3. Confirm the following files are present:
      cert.pem
      chain.pem
      fullchain.pem
      privkey.pem
  2. Verify Certificate Installation
    1. Review the certificate expiration date.
      Command:
      openssl x509 \
      -in /etc/letsencrypt/live/website.okstate.edu/cert.pem \
      -noout -dates
    2. Verify HTTPS connectivity.
      Command:
      curl -Iv https://website.okstate.edu
    3. Confirm:
      1. The certificate is trusted.
      2. The hostname is correct.
      3. The expiration date is correct.
      4. No certificate warnings are reported.
    4. Verify the website loads successfully in a web browser.

 

 

Details

Details

Article ID: 21257
Created
Mon 8/3/26 1:24 PM
Modified
Tue 8/25/26 3:15 PM