# Automate renewing SSL Certificate with AWS

**URL:** <https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011>\
**Category:** Help\
**Created:** [October 2, 2023, 9:39am UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011 "2023-10-02T09:39:26Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![milan.m](https://avatars.discourse-cdn.com/v4/letter/m/4491bb/32.png) [@milan.m](https://community.letsencrypt.org/u/milan.m)\
**Post date:** [October 2, 2023, 9:39am UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/1 "2023-10-02T09:39:26Z")

</div>

Hi guys,

My domain is [milan.com](http://milan.com)  
The instance is: amazon linux  
So every 3 months i need to renew my ssl certificate and i am doing it manually.  
So in AWS I have hosted zones -\> [milan.com](http://milan.com)  
The steps i am doing is -\>  
When i am in the instance logged i enter this command: sudo certbot --manual --preferred-challenges dns certonly. Then I manually enter all the domains that i need to be renewed like [alpha.milan.com](http://alpha.milan.com), [milan.com](http://milan.com), [inter.milan.com](http://inter.milan.com) and etc. (\*.milan.com ). Then the output provide me TXT Records for every domain which i need to change txt record in the AWS. Then after i change all txt record in the AWS, i restart the httpd service on the instance.  
!!! [milan.com](http://milan.com) is example !!!

Best Regards,  
Milan

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 2, 2023, 10:58am UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/2 "2023-10-02T10:58:38Z")

</div>

AWS is Route53, right? Certbot has a DNS plugin for Route53, so you might be able to automate things. See [Welcome to certbot-dns-route53’s documentation! — certbot-dns-route53 0 documentation](https://certbot-dns-route53.readthedocs.io/en/stable/) for more information.

Note that when/if you've got the DNS plugin working, it should be enough to run `sudo certbot renew` to renew your certificate(s). This is usually done with a cronjob or systemd timer, which may or may not be already installed, depending on how you've installed Certbot to begin with.

---

<div class="post-metadata">

**Author:** ![milan.m](https://avatars.discourse-cdn.com/v4/letter/m/4491bb/32.png) [@milan.m](https://community.letsencrypt.org/u/milan.m)\
**Post date:** [October 20, 2023, 11:02am UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/3 "2023-10-20T11:02:33Z")

</div>

[Automating DNS-challenge based LetsEncrypt certificates with AWS Route 53 | by John Rix | Medium](https://johnrix.medium.com/automating-dns-challenge-based-letsencrypt-certificates-with-aws-route-53-8ba799dd207b) , do you think that this state will do the job ? Only to modify the cron job for long time and add a script for the httpd service to restart. Do you think 1 or 2 minutes are okay for the httpd service to restart after the cron job for the renewing?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 20, 2023, 11:18am UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/4 "2023-10-20T11:18:49Z")

</div>

> [@milan.m](#):
>
> Do you think 1 or 2 minutes are okay for the httpd service to restart after the cron job for the renewing?

I think you are overcomplicating the process.  
A cron job that runs immediately after renewal attempts would reload/restart the httpd service way too often.  
Certs last 90 days.  
They only need to be renewed after 60 days [default].  
The renewal process runs and first checks to see if any certs need to be renewed.  
Most of the times, there is nothing to renew.

Either:

- use a `deploy-hook` to reload/restart the httpd service [which is only triggered when a cert is actually renewed]
- schedule the reload/restart without any regard to the cert state [like once a week (every week) during off hours]  
The cert should renew 30 days ahead of expiry - that should cover four reloads/restarts.

---

<div class="post-metadata">

**Author:** ![milan.m](https://avatars.discourse-cdn.com/v4/letter/m/4491bb/32.png) [@milan.m](https://community.letsencrypt.org/u/milan.m)\
**Post date:** [October 20, 2023, 12:02pm UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/5 "2023-10-20T12:02:59Z")

</div>

Hello,  
Thanks for the answer 🙂 So I entered the command sudo certbot certonly --dns-route53 --dns-route53-propagation-seconds 30 -d [domain.com](http://domain.com) -d [up.domain.com](http://up.domain.com) and all went great and successfully 🙂 So what i understand from your message is that , every 60 days the certbot will automatically update the certificates without nothing additional to do after the command that I entered before ? No need anything else to do ? Only adding the deploy-hook or schedule reload

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 20, 2023, 12:15pm UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/7 "2023-10-20T12:15:40Z")

</div>

Yes.  
That command will only renew the cert ["certonly"].  
So, at some point you must update whatever is using the old cert to use the updated cert.  
Using a `deploy-hook` is ideal - but there plenty of ways to get [essentially] the same result.

---

<div class="post-metadata">

**Author:** ![milan.m](https://avatars.discourse-cdn.com/v4/letter/m/4491bb/32.png) [@milan.m](https://community.letsencrypt.org/u/milan.m)\
**Post date:** [October 20, 2023, 12:34pm UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/8 "2023-10-20T12:34:39Z")

</div>

Okay, thanks a lot 🙂 You helped me a lot with the other person. Have a nice day.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 20, 2023, 12:35pm UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/9 "2023-10-20T12:35:11Z")

</div>

You too!  
Cheers from Miami 🍻

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 19, 2023, 12:35pm UTC](https://community.letsencrypt.org/t/automate-renewing-ssl-certificate-with-aws/206011/10 "2023-11-19T12:35:29Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
