sudo certbot -d $DOMAIN -d $WILDCARD --manual --preferred-challenges dns certonly

Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator manual, Installer None
Starting new HTTPS connection (1):
Cert not yet due for renewal

You have an existing certificate that has exactly the same domains or certificate name you requested and isn't close to expiry.
(ref: /etc/letsencrypt/renewal/

1: Keep the existing certificate for now
2: Renew & replace the cert (limit ~5 per 7 days)
Amazon Lightsail LAMP7 instance

Welcome to Ubuntu 16.04.6 LTS (GNU/Linux 4.4.0-1109-aws x86_64)

Amazon Lightsail LAMP7

I can SUDO

certbot 0.31.0

I have followed the instructions at:

In detail with this domain and several others but never had an issue. I accidentally let the certificate expire on this domain and following these steps I'm still getting that the cert is expired when I go to the site.
Do you have a specific hostname that showed certificate invalid?
Currently your root domain has a valid certificate that'll expire on Sep 30 12:42:32 2020 GMT.

If you successfully installed your certificate and reloaded your webserver, there might be cache to your local browser that still use the old certificate. In that case, you can try to use a online certificate checking tool such as or use another browser to verify your certificate deployment.

Thank you


Hi Sevenzhu, my apologies… It looked like it just took a very long time to propagate.

I did clear brower caches and it suddenly started working.

One thing I did do differently was since the cert had expired completely I followed the final steps in that link I posted to copy the cert files into apache and restart.

That may have been what was needed. Not sure.


