Certificates - CertiNext - How to Configure Automatic Certificate Deployment for Apache HTTPD Using Certbot

Summary

This article explains how to configure Apache HTTPD to use Certbot-managed certificates and automatically deploy renewed certificates obtained through the CertiNext ACME service.

Body

Self-Help Article (External)

Purpose

This article explains how to configure Apache HTTPD to use Certbot-managed certificates and automatically deploy renewed certificates obtained through the CertiNext ACME service.

Requirements

Step-by-Step Procedures

Step 1: Configure Apache HTTPD to Use the Certificate

  1. Identify the certificate name.
    Command:

    sudo certbot certificates
  2. Review the results and identify the certificate name associated with the website.
  3. Open the HTTPS virtual host configuration file.
    Command:

    sudo vi /etc/httpd/conf.d/ssl.conf
  4. Configure Apache HTTPD to use the Certbot-managed certificate files.
    Configuration:

    SSLCertificateFile /etc/letsencrypt/live/<certificate-name>/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/<certificate-name>/privkey.pem
  5. Replace <certificate-name> with the certificate name identified in Step 1.
  6. Save the configuration file.

    Notes:
    - 
    Always reference the files located in /etc/letsencrypt/live/.
    - Do not copy certificates to alternate locations unless required by a specific application.
    - Certbot automatically updates these files when certificates are renewed.

 

Step 2: Validate the Apache Configuration
  1. Verify the Apache HTTPD configuration syntax.
    Command:
    sudo apachectl configtest
  2. Review the results.
  3. Confirm the following message is displayed:
    Syntax OK
  4. Resolve any reported errors before proceeding.

 

Step 3: Reload Apache HTTPD
  1. Reload the Apache HTTPD service.
    Command:
    sudo systemctl reload httpd
    Note: This procedure uses systemctl reload httpd, not systemctl restart httpd. A reload allows Apache to begin using the renewed certificate without disconnecting active users or causing a service outage.​​
  2. Verify the Apache HTTPD service is running.
    Command:
    systemctl status httpd
  3. Confirm the service status is active (running).
Step 4: Configure Automatic Certificate Deployment (Deploy Hook) Following Renewal
  1. Create the Certbot deploy hook directory if it does not already exist.
    Command:
    sudo mkdir -p /etc/letsencrypt/renewal-hooks/deploy
  2. Create a deployment hook script.
    Command:
    sudo vi /etc/letsencrypt/renewal-hooks/deploy/reload-httpd.sh
  3. Add the following content:
    #!/bin/bash
    systemctl reload httpd
  4. Save the file.
  5. Make the script executable.
    Command:
    sudo chmod 755 /etc/letsencrypt/renewal-hooks/deploy/reload-httpd.sh

    Notes:
    - The manual reload performed in Step 3 applies the Apache configuration changes made during the initial certificate deployment.
    - Certbot automatically runs deployment hook scripts located in
    /etc/letsencrypt/renewal-hooks/deploy/ after a successful certificate renewal.
    - Reloading Apache HTTPD causes the web server to begin using the renewed certificate.
    - Existing client connections are not interrupted during a reload operation.
    - Future certificate renewals will automatically trigger systemctl reload httpd through this deploy hook, allowing Apache to begin using the renewed certificate without requiring manual intervention
Step 5: Test Automatic Certificate Deployment
  1. Run a simulated certificate renewal.
    Command:

    sudo certbot renew --dry-run
  2. Review the results.
  3. Confirm the following message is displayed:
    Congratulations, all simulated renewals succeeded.
  4. Verify that no Apache HTTPD errors are reported during the renewal process.
  5. Resolve any reported errors before relying on automatic certificate deployment in production.

    Notes:
    - The --dry-run option performs a simulated certificate renewal for testing purposes.
    - No new certificate is permanently installed during the test.
    - Successful completion confirms that automatic certificate renewal and deployment are expected to function correctly when an actual renewal occurs.
Automatic Certificate Deployment Workflow for a Website
Certbot-renew.timer runs
↓
Certbot checks certificate expiration
↓
Certificate eligible for renewal?
↓
No → Renewal check completes
↓
Yes
↓
Certificate is renewed
↓
Certbot updates certificate files in
/etc/letsencrypt/live/<certificate-name>/
↓
Certbot executes deploy hook
(reload-httpd.sh)
↓
systemctl reload httpd
↓
Apache reloads configuration
↓
Apache reads the updated certificate files
↓
Website serves the renewed certificate


Notes:
- The timing of certificate renewal and any associated Apache HTTPD reload is controlled by the certbot-renew.timer schedule.
- Routine renewal checks that do not result in a certificate renewal do not trigger an Apache HTTPD reload.
Additional Information
  1. View Certbot Deployment Hooks
    Command:
    ls -l /etc/letsencrypt/renewal-hooks/deploy/
  2. Manually Reload Apache HTTPD
    Command:
    sudo systemctl reload httpd
  3. View Apache HTTPD Service Logs
    Command:
    sudo journalctl -u httpd

 

 

Details

Details

Article ID: 21262
Created
Wed 8/5/26 1:21 PM
Modified
Tue 8/25/26 3:16 PM