# Best practice for adding sub-domain certificates?

**URL:** <https://community.letsencrypt.org/t/best-practice-for-adding-sub-domain-certificates/7144>\
**Category:** Uncategorized\
**Created:** [December 16, 2015, 6:04am UTC](https://community.letsencrypt.org/t/best-practice-for-adding-sub-domain-certificates/7144 "2015-12-16T06:04:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dominikvpb](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dominikvpb/32/3351_2.png) [@dominikvpb](https://community.letsencrypt.org/u/dominikvpb)\
**Post date:** [December 16, 2015, 6:04am UTC](https://community.letsencrypt.org/t/best-practice-for-adding-sub-domain-certificates/7144/1 "2015-12-16T06:04:43Z")

</div>

I have successfully setup a site with two subdomains, using the standalone option

`./letsencrypt-auto certonly -a standalone -d example.com -d www.example.com -d sub1.example.com`

Everything is working great so far, and the combined certificate is in the live/example.com folder. What is the best approach now if I would like to add another subsite, i.e. [sub2.example.com](http://sub2.example.com)? Is it better to run the full command again, just adding the site?

`./letsencrypt-auto certonly -a standalone -d example.com -d www.example.com -d sub1.example.com -d sub2.example.com`

Or is it better to run letsencrypt with only the new domain?

`./letsencrypt-auto certonly -a standalone -d sub2.example.com`

Does it make any difference at all? Is there a best practice?

Thanks!!

---

<div class="post-metadata">

**Author:** ![btmash](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/btmash/32/4434_2.png) [@btmash](https://community.letsencrypt.org/u/btmash)\
**Post date:** [January 21, 2016, 2:27am UTC](https://community.letsencrypt.org/t/best-practice-for-adding-sub-domain-certificates/7144/2 "2016-01-21T02:27:23Z")

</div>

The big thing I notice is that it will try to create the certs again or prompt you asking what to do about the existing certs. You could pass the --keep or --renew-by-default flags to keep existing non-expired certs or replace them, accordingly. So you could put them all in the same line with --keep and it won’t replace the certs. I **think** that is a better approach but there might be better reasons from others on why not.

---

<div class="post-metadata">

**Author:** ![rllmwm](https://avatars.discourse-cdn.com/v4/letter/r/e79b87/32.png) [@rllmwm](https://community.letsencrypt.org/u/rllmwm)\
**Post date:** [February 14, 2016, 6:51pm UTC](https://community.letsencrypt.org/t/best-practice-for-adding-sub-domain-certificates/7144/3 "2016-02-14T18:51:05Z")

</div>

I just ran one of the server plugin ones and it took care of adding a new subdomain to the existing cert for renewal. Really easy.

e.g.

`letsencrypt --apache`

---

<div class="post-metadata">

**Author:** ![seanmavley](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/seanmavley/32/5594_2.png) [@seanmavley](https://community.letsencrypt.org/u/seanmavley)\
**Post date:** [March 2, 2016, 2:50pm UTC](https://community.letsencrypt.org/t/best-practice-for-adding-sub-domain-certificates/7144/4 "2016-03-02T14:50:31Z")

</div>

So how does it eventually become?

`./letsencrypt-auto certonly -a standalone -d example.com -d www.example.com -d sub1.example.com -d sub2.example.com --keep --renew-by-default`

OR

`./letsencrypt-auto certonly -a standalone -d sub2.example.com --keep --renew-by-default`

?

---

<div class="post-metadata">

**Author:** ![dominikvpb](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dominikvpb/32/3351_2.png) [@dominikvpb](https://community.letsencrypt.org/u/dominikvpb)\
**Post date:** [March 2, 2016, 3:54pm UTC](https://community.letsencrypt.org/t/best-practice-for-adding-sub-domain-certificates/7144/5 "2016-03-02T15:54:50Z")

</div>

For the renewal I just ran the original command again:

`./letsencrypt-auto certonly -a standalone -d example.com -d www.example.com`

no further flags like --renew-by-default. Seemed to work just fine and the renewed certificates are working.

---

<div class="post-metadata">

**Author:** ![wbargent](https://avatars.discourse-cdn.com/v4/letter/w/67e7ee/32.png) [@wbargent](https://community.letsencrypt.org/u/wbargent)\
**Post date:** [April 22, 2016, 6:29am UTC](https://community.letsencrypt.org/t/best-practice-for-adding-sub-domain-certificates/7144/6 "2016-04-22T06:29:12Z")

</div>

So what would happen if I decided I no longer needed one of the domains/subs and I took it out of the renewal cron, would it simply just remove it and carry on renewing the rest?
