# Certbot as python library?

**URL:** <https://community.letsencrypt.org/t/certbot-as-python-library/147465>\
**Category:** Client dev\
**Created:** [March 15, 2021, 10:28am UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465 "2021-03-15T10:28:23Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![NigelM](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nigelm/32/48087_2.png) [@NigelM](https://community.letsencrypt.org/u/NigelM)\
**Post date:** [March 15, 2021, 10:28am UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/1 "2021-03-15T10:28:23Z")

</div>

Is certbot available as a library, or are there any plans for that?

We're looking at using Azure Application Gateway, so we're going to have to do something to auotomate this. Calling certbot from a script is doable, but then we have to make .pfx files etc. Ideally this is something I'd like to do from python using certbot and pyOpenSSL then use the azure sdk to upload them and other bits to set up the DNS challenge.

Also renewals look like they might be trickier to automate using the command line options as well (though I confess I've not dug into that too much yet)

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [March 15, 2021, 10:39am UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/2 "2021-03-15T10:39:55Z")

</div>

I think that there are some good options (other than Certbot) if you're looking for Azure automation.

The PowerShell library [Posh-ACME](https://github.com/rmbolger/Posh-ACME) might be a good choice, since I think that will allow you to do everything end-to-end for your Azure Application Gateway in a single PS script?

[Certify the Web](https://certifytheweb.com) might be a good choice as well, because it has built-in support for automated deployment to Azure Key Vault, which I think connects with Azure Application Gateway.

There are a few other Windows options in the [client list](https://letsencrypt.org/docs/client-options/) as well.

Certbot does have an `acme` Python library you can use, but I think there's probably better tools for the job in this case.

---

<div class="post-metadata">

**Author:** ![NigelM](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nigelm/32/48087_2.png) [@NigelM](https://community.letsencrypt.org/u/NigelM)\
**Post date:** [March 15, 2021, 11:41am UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/3 "2021-03-15T11:41:37Z")

</div>

Thank you. I had seen Posh-ACME but it didn't do renewals from what I could see (ok so we could just get another one each time).  
We use Certify The Web now and I wasn't aware that would push to key vault so that's very useful to know. Will look into that.  
We also have to do end-to-end encryption as well probably which adds to the fun but going to investigate self-signed certs for the internal hop.

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [March 15, 2021, 11:45am UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/4 "2021-03-15T11:45:22Z")

</div>

A "renewal" is just an easy shorthand for "get another certificate for the same names"; there's really nothing protocol-wise that makes something a renewal rather than a "new" certificate. It's just handy to have that shorthand for a lot of things, and of course many ACME clients have a concept of storing your configuration so that a "renewal" happens the same way as the last time.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [March 15, 2021, 12:04pm UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/5 "2021-03-15T12:04:10Z")

</div>

I think Posh-ACME does [have renewals](https://github.com/rmbolger/Posh-ACME/blob/main/Tutorial.md#renewals-and-deployment) so one doesn't have to go through the `New-PACertificate` steps every time:

> `Submit-Renewal` will only return PACertificate objects for certs that were actually renewed successfully. So the typical template for a renew/deploy script might look something like this.

```powershell
Set-PAOrder example.com
if ($cert = Submit-Renewal) {
    # do stuff with $cert to deploy it
}

```

Though if Certify makes the job easier, one may as well go with that.

---

<div class="post-metadata">

**Author:** ![NigelM](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nigelm/32/48087_2.png) [@NigelM](https://community.letsencrypt.org/u/NigelM)\
**Post date:** [March 15, 2021, 12:14pm UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/6 "2021-03-15T12:14:07Z")

</div>

@petercooperjr I thought a renewal is slightly different, in that Let's Encrypt then doesn't send reminders saying the old one is about to expire? This is extrapolating from guesses about which emails I see coming in to the shared email we use for this (when we've had to add a domain and so have to get a new one) so I should probably check my assumptions.

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [March 15, 2021, 12:35pm UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/7 "2021-03-15T12:35:03Z")

</div>

You're correct of course. A renewal, in the sense of "another certificate was created with the same set of domain names", _are_ tracked differently for rate limit purposes, and you get a reminder email if a renewal certificate wasn't created near the end of a cert's expiration. But in terms of what's technically happening, of what your ACME client requests to the server and the certificate it gets back, there's no difference between a "new" certificate and a "renewal" certificate. It's just that some policies that look at them differently, if that makes sense.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 15, 2021, 1:25pm UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/8 "2021-03-15T13:25:59Z")

</div>

And to make it even a little bit more explicit: it doesn't matter _how_ you renew (by the "renew option" of an ACME client or if you use the "get me a new certificate" option), as long as the contents of the certificate (hostnames) are the same, Let's Encrypt will see the certificate as a renewal and won't send an e-mail.

"Trick" question to @NigelM: if you somehow manage to confuse your ACME client and mess up the hostnames of a certain certificate and consequentially use the " **renew**" feature of your ACME client, will you receive an e-mail from Let's Encrypt when the original certificate is close to expiry? 😉

---

<div class="post-metadata">

**Author:** ![NigelM](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nigelm/32/48087_2.png) [@NigelM](https://community.letsencrypt.org/u/NigelM)\
**Post date:** [March 15, 2021, 5:37pm UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/9 "2021-03-15T17:37:50Z")

</div>

Thanks for the clarification. As I say I've not had the time to fully investigate - had enough trying to ingest a host of Azure information this last few weeks. From what you say @Osiris I assume we _would_ get an email as that is triggered by matching on hostnames and if they are messed up then it's seen as a new one?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 15, 2021, 6:18pm UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/10 "2021-03-15T18:18:42Z")

</div>

> [@NigelM](#):
>
> From what you say @Osiris I assume we _would_ get an email as that is triggered by matching on hostnames and if they are messed up then it's seen as a new one?

Absolutely correct!&nbsp;

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 19, 2021, 2:39am UTC](https://community.letsencrypt.org/t/certbot-as-python-library/147465/13 "2021-04-19T02:39:41Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
