# Automating renewal process

**URL:** <https://community.letsencrypt.org/t/automating-renewal-process/14145>\
**Category:** Server\
**Created:** [April 12, 2016, 10:51pm UTC](https://community.letsencrypt.org/t/automating-renewal-process/14145 "2016-04-12T22:51:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kghbln](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kghbln/32/6641_2.png) [@kghbln](https://community.letsencrypt.org/u/kghbln)\
**Post date:** [April 12, 2016, 10:51pm UTC](https://community.letsencrypt.org/t/automating-renewal-process/14145/1 "2016-04-12T22:51:22Z")

</div>

I am having multiple issues when trying to obtain a cert and automatize. So my question is:

The first step is to obtain the cert. I only manage to get it working like this:  
`./letsencrypt-auto certonly --webroot -w /var/www/.../action -d example.org -d www.example.org`  
All other methods fail on me. Whatever. No problem. I have my cert.

The next step is to manually configure the VirtualHost. No problem. I can do this to crank things up initially.

The third step is to automatize the renewal. Things like

`./letsencrypt-auto certonly --apache --renew-by-default -d example.org -d www.example.org`  
fail on me so I again only got this working successfully:

./letsencrypt-auto certonly --renew-by-default --webroot -w /var/www/…/action -d [example.org](http://example.org) -d [www.example.org](http://www.example.org)

In case I add this to a cronjob. Do I still have to do work manually on every renewal or does it just replace the old certs with the new ones. I am not sure how the server gets the new cert data in. Do I have to reaload the webserver at every renewal for the third step stated here?

---

<div class="post-metadata">

**Author:** ![DarkSteve](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/darksteve/32/1050_2.png) [@DarkSteve](https://community.letsencrypt.org/u/DarkSteve)\
**Post date:** [April 13, 2016, 2:14am UTC](https://community.letsencrypt.org/t/automating-renewal-process/14145/2 "2016-04-13T02:14:40Z")

</div>

I just replied to this in the [other thread you commented on](https://community.letsencrypt.org/t/how-to-resolve-the-correct-zname-not-found-for-tls-sni-challenge-error-when-i-try-renew-certificate/9405/38). Sorry, I didn’t realise you’d started a new thread.

To answer the first part, basically you can’t mix “certonly” with the “-apache” flag. The apache flag alters your Apache config, so it’s not “only” obtaining a cert. Certonly works with “standalone” or “webroot”.

To renew, just use the option “renew” and nothing else. That is, “letsencrypt renew”. Create a cron job or something and you’re done! The guide advises that you run the cron daily, but I’m running it weekly (I figure if the LE system is down, I still have two or three attempts before expiry).

There’s also a new flag introduced in v0.5 which allows you to run the command silently, so you won’t get an email if nothing goes wrong. (Sorry, I can’t remember it off the top of my head.)

Oh, and don’t forget to add “apache reload” or “postfix reload” to your cron job 😉

---

<div class="post-metadata">

**Author:** ![kghbln](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kghbln/32/6641_2.png) [@kghbln](https://community.letsencrypt.org/u/kghbln)\
**Post date:** [April 13, 2016, 6:47am UTC](https://community.letsencrypt.org/t/automating-renewal-process/14145/3 "2016-04-13T06:47:49Z")

</div>

The original rationale of the post to the other thread was the “Correct zName not found for TLS SNI challenge” issue covered and basically still not solved there. Since I have multiple further issues I did not even attempt to ask about I somehow ended up crossposting due to not knowing where to start with all these issues. Apart from that with all these commands I am sharing here are from just following step by step tutorials “out there”. So there is obviously heaps of b… Never mind. You covered what I wanted to know and what I do wrong. 🙂 Thank you for your help!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 13, 2016, 6:47am UTC](https://community.letsencrypt.org/t/automating-renewal-process/14145/4 "2016-05-13T06:47:54Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
