Mohammad Ali

Business & Digital Consultant

IT & Cloud Consultant

Career Growth Mentor

Sales & Strategy Advisor

0

No products in the cart.

Mohammad Ali

Business & Digital Consultant

IT & Cloud Consultant

Career Growth Mentor

Sales & Strategy Advisor

Blog Post

Automating SSL Certificate Renewal with Let’s Encrypt and Certbot on Ubuntu Servers

September 9, 2026 Uncategorized

Managing SSL certificates manually on Ubuntu web servers can be daunting, especially when servers host production applications with high availability requirements. Letting certificates expire can lead to downtime, security warnings, and loss of client trust. Thankfully, Let’s Encrypt provides free SSL certificates, and, combined with Certbot automation on Ubuntu, you can eliminate manual intervention and achieve robust zero-downtime certificate renewals. This guide offers a practical, step-by-step walkthrough to automate Let’s Encrypt SSL certificate renewal on Ubuntu servers—covering Certbot setup, fully automated renewal, cron job management, and troubleshooting for real-world, production-grade deployments.

What Is Let’s Encrypt and Certbot?

Let’s Encrypt is a widely-adopted Certificate Authority that issues free, trusted SSL/TLS certificates. Its short 90-day certificate validity incentivizes automation to maintain continuous security.

Certbot is the official, open-source tool provided by the EFF to request, install, and renew Let’s Encrypt certificates. It supports major web servers like Apache and NGINX and integrates well with automation scripts and cron jobs.

Prerequisites

  • Ubuntu 20.04 LTS (Focal Fossa) or later (steps may be similar for earlier versions)
  • Root or sudo privileges on your server
  • A registered domain name pointed to your server’s public IP (DNS already set up)
  • An existing web server (NGINX or Apache) configured to serve your site
  • Port 80 (http) and port 443 (https) open in your firewall

Step-by-Step Implementation

1. Install Certbot and the Required Plugins

Begin by installing Certbot. You’ll also need the plugin that matches your web server: python3-certbot-nginx for NGINX, or python3-certbot-apache for Apache.

# For NGINX
sudo apt update
sudo apt install certbot python3-certbot-nginx

# For Apache
sudo apt update
sudo apt install certbot python3-certbot-apache

These packages equip your system to both obtain and manage SSL certificates on Ubuntu efficiently.

2. Obtain Your Initial SSL Certificate

Before automating renewals, make sure Certbot can successfully request and install a certificate for your domain. Replace yourdomain.com with your actual domain name.

# For NGINX
sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com

# For Apache
sudo certbot --apache -d yourdomain.com -d www.yourdomain.com

This command:

  • Requests certificates for your domain and any aliases (like www)
  • Automatically updates your web server configuration for HTTPS
  • Performs required HTTP-01 validation

If you prefer, you can use the certonly mode to just obtain a certificate (without modifying web server configs):

sudo certbot certonly --nginx -d yourdomain.com -d www.yourdomain.com

3. Test Manual Renewal

It’s critical to understand and verify renewal before trusting automation. Run a dry-run renewal:

sudo certbot renew --dry-run

This will simulate the renewal process without actually changing certificates, highlighting any issues (like misconfigured validation, firewall blocks, or incorrect web server integration).

4. Automate Certificate Renewals with Systemd (Preferred on Ubuntu 20.04+)

Modern Ubuntu versions install a timer with Certbot that uses Systemd to run twice daily. You can check its status with:

systemctl list-timers | grep certbot

You should see output showing certbot.timer is enabled, triggering certbot.service automatically. No extra cron job is needed unless you have a legacy configuration or prefer explicit cron.

5. Automating Renewals with Cron (Alternative/Legacy Approach)

If you want to create or confirm a custom cron job for automated certificate renewal:

  1. Edit the root crontab (not your personal crontab):
    sudo crontab -e
  2. Add the following line to check for renewal twice daily:
    0 3,15 * * * certbot renew --quiet --deploy-hook "systemctl reload nginx"
    • For Apache, replace nginx with apache2:
    • 0 3,15 * * * certbot renew --quiet --deploy-hook "systemctl reload apache2"

What this cron job does:

  • Runs certbot renew silently at 3:00 am and 3:00 pm every day
  • Only renews certificates that are close (<30 days) to expiration
  • After renewal, automatically reloads the appropriate web server to apply the new certificate without downtime

Note: Only use automation in one place (Systemd or cron), not both simultaneously. Systemd is preferred for Ubuntu 20.04+.

6. Verifying Renewal and Automatic Reload

You can confirm the scheduled automation and its results in several ways:

  • Check the renewal timer or cron job logs for recent activity
  • Look in /var/log/letsencrypt/letsencrypt.log for detailed operation history
  • After a successful renewal, verify web server reloads correctly and new certificates are served:
    • sudo systemctl status nginx or sudo systemctl status apache2
    • Use openssl to inspect the certificate expiry date:
      echo | openssl s_client -connect yourdomain.com:443 2>/dev/null | openssl x509 -noout -dates
      

7. Key Tips for Production-Ready Certbot Renewal Automation

  • Always verify initial issuance and renewal with --dry-run in staging before production
  • Regularly monitor letsencrypt.log for renewal failures or web server reload errors
  • Keep certbot, plugins, and your web server up-to-date for continued compatibility
  • If you use firewalls like UFW or security groups, ensure ports 80 and 443 remain open for renewal validation
  • Use --deploy-hook in certbot renew to reload services and run additional scripts if necessary
  • If running behind load balancers or reverse proxies, make sure traffic for validation challenges reaches the correct server
  • Consider automating notifications for renewal errors (e.g., via email or monitoring systems)

Troubleshooting Common Issues

Issue Likely Cause How to Fix
Renewal fails with validation errors DNS misconfiguration, closed ports, or no HTTP access Ensure DNS points to server, ports 80/443 are open, and no firewall/intermediate devices block traffic
Web server doesn’t reload after renewal Missing or incorrect --deploy-hook or misconfigured reload command Check deploy-hook and server status, review renewal logs for details
Automated renewal not running Systemd timer or cron not set up, or conflicting configs Check systemctl list-timers | grep certbot or crontab -l and enable one method only
Renewal fails with “Too Many Requests” error Exceeded Let’s Encrypt rate limits due to frequent or repetitive requests Test with --dry-run, space out requests, and review rate limits documentation

Security and Best Practices

  • Never check SSL private keys into source control or share them publicly
  • Limit root access and use sudo for certificate operations
  • Restrict /etc/letsencrypt permissions to root only
  • Monitor certificate expiry dates and configure alerting in production
  • Regularly review server security and keep all packages updated
  • If you automate across fleets or in cloud environments, consider using tools like Ansible, Chef, or Terraform for inventory-level management

Conclusion

Automating SSL certificate renewal with Let’s Encrypt and Certbot is essential for maintaining continuous security and uptime on Ubuntu servers. By following the steps above, you can confidently automate certificate management, avoiding outages and manual work. Ensure you leverage either Certbot’s built-in Systemd automation or well-configured cron jobs, and always test and monitor renewal processes for peace of mind in any production setup. Reliable SSL management is a cornerstone of professional DevOps and system administration—don’t let expiring certificates become a point of failure.

Write a comment