# Certbot - List of Managed Certificates After Renewals

**URL:** <https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075>\
**Category:** Issuance Tech\
**Created:** [March 31, 2017, 3:29pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075 "2017-03-31T15:29:38Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![immanens](https://avatars.discourse-cdn.com/v4/letter/i/7feea3/32.png) [@immanens](https://community.letsencrypt.org/u/immanens)\
**Post date:** [March 31, 2017, 3:29pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/1 "2017-03-31T15:29:38Z")

</div>

Hi. My server renew all certificates, and I have to get a list of “new” certificates, in order to send them to right servers ( yes, certificates and servers are not stored at same server).

But how can I get new certificates list? (another way then a ugly egrep ‘(hostname (success)’ logfile )

thanks a lot

---

<div class="post-metadata">

**Author:** ![MitchellK](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mitchellk/32/18339_2.png) [@MitchellK](https://community.letsencrypt.org/u/MitchellK)\
**Post date:** [March 31, 2017, 3:33pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/2 "2017-03-31T15:33:34Z")

</div>

/var/log/certbot-renew.log ???

---

<div class="post-metadata">

**Author:** ![jmorahan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jmorahan/32/1873_2.png) [@jmorahan](https://community.letsencrypt.org/u/jmorahan)\
**Post date:** [March 31, 2017, 5:46pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/3 "2017-03-31T17:46:11Z")

</div>

Assuming you’re using Certbot, there’s a `--renew-hook` option that passes environment variables `RENEWED_LINEAGE` and `RENEWED_DOMAINS` to the command or script you specify. See `certbot --help renew` for more detail. You could do the copying to different servers from within such a script, or just save the list of domains for later use.

---

<div class="post-metadata">

**Author:** ![immanens](https://avatars.discourse-cdn.com/v4/letter/i/7feea3/32.png) [@immanens](https://community.letsencrypt.org/u/immanens)\
**Post date:** [March 31, 2017, 6:36pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/4 "2017-03-31T18:36:36Z")

</div>

Yes, I use cerbot and I should copy new certs to other servers. So I’ve to know, Which one to copy after midnight auto renewal.  
I’ll take a look for RENEWED\_LINEAGE and RENEWED\_DOMAINS. thanks

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [April 1, 2017, 10:05am UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/5 "2017-04-01T10:05:12Z")

</div>

Hi @immanens

> certbot certificates

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/e/e3206b8a5eb9c0ae8d57f32c4e9284b9daf0d86e.png)

Andrei

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [April 1, 2017, 5:06pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/6 "2017-04-01T17:06:55Z")

</div>

I think `RENEWED_LINEAGE` and `RENEWED_DOMAINS` are more useful for scripting here. With `certbot certificates` you would have to do some further parsing to figure out what changed, but Certbot is already willing to tell the hook script what changed directly with the `RENEWED_` variables.

---

<div class="post-metadata">

**Author:** ![immanens](https://avatars.discourse-cdn.com/v4/letter/i/7feea3/32.png) [@immanens](https://community.letsencrypt.org/u/immanens)\
**Post date:** [April 3, 2017, 9:05am UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/7 "2017-04-03T09:05:51Z")

</div>

> [@schoen](#):
>
> RENEWED\_DOMAINS

I tried to echo RENEWED\_ in a hook script such like this  
/usr/local/sbin/certbot-auto renew --dry-run --renew-hook /usr/local/bin/certbot\_hook.sh  
but hook is not called in try run mode, and I don't have hostname to renew in my pocket

> Dry run: skipping renewal hook command: /root/bin/certbot\_hook.sh

is there anyway to test hook option and to get those variables?

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [April 3, 2017, 6:13pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/8 "2017-04-03T18:13:16Z")

</div>

I don’t think Certbot offers a way to test hooks without performing an actual renewal. If you’re familiar with Python programming, you could edit the code to change the dry run behavior so that it does run hooks.

---

<div class="post-metadata">

**Author:** ![zjs](https://avatars.discourse-cdn.com/v4/letter/z/51bf81/32.png) [@zjs](https://community.letsencrypt.org/u/zjs)\
**Post date:** [April 3, 2017, 6:35pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/9 "2017-04-03T18:35:12Z")

</div>

> [@immanens](#):
>
> I don't have hostname to renew

You may find the `--force-renewal` option useful, which will cause certificates to be renewed regardless of whether they are near expiry.

(Just be careful of the [rate limits](https://letsencrypt.org/docs/rate-limits/)!)

---

<div class="post-metadata">

**Author:** ![immanens](https://avatars.discourse-cdn.com/v4/letter/i/7feea3/32.png) [@immanens](https://community.letsencrypt.org/u/immanens)\
**Post date:** [April 4, 2017, 8:53am UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/10 "2017-04-04T08:53:01Z")

</div>

OK. I successfully called a hook script like this  
/usr/local/sbin/certbot-auto renew --renew-hook “bash /root/bin/certbot\_hook.sh” \> /var/log/certbot.log  
not sure that “bash …” is necessary.  
and the hook script is like this:  
#!/bin/bash  
DATE=`date +"%Y%m%d-%H-%m"`  
BASE\_CERTS\_DIR="/etc/letsencrypt/archive"  
CERTFILE=`ls -Art $BASE_CERTS_DIR/$RENEWED_DOMAINS/cert* | tail -n 1`  
KEYFILE=`ls -Art $BASE_CERTS_DIR/$RENEWED_DOMAINS/privkey* | tail -n 1`  
bash /usr/local/sbin/ssl.sh renew $RENEWED\_DOMAINS $CERTFILE $KEYFILE  
echo $RENEWED\_DOMAINS “$DATE” \>\> /var/log/renew.log

[ssl.sh](http://ssl.sh) is a homemade script who uses aws cli to update ELB certificates. I figured that I might use env variable to get certificate path … ok I’ll update that later, thanks for your helps. hope this can help someone else.  
regards.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [April 4, 2017, 5:30pm UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/11 "2017-04-04T17:30:22Z")

</div>

You might want to be careful that your scripts apparently don’t mention the chain file anywhere. If Let’s Encrypt changes which intermediate it issues under (which has happened once so far), you’ll have a chain mismatch on ELB.

I speculate this is likely to happen about once every 2-3 years, but it’s nice to be prepared. 🙂

---

<div class="post-metadata">

**Author:** ![mkovacic](https://avatars.discourse-cdn.com/v4/letter/m/e5b9ba/32.png) [@mkovacic](https://community.letsencrypt.org/u/mkovacic)\
**Post date:** [April 6, 2017, 11:44am UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/12 "2017-04-06T11:44:04Z")

</div>

Hi,

Why would you even want to know if certs are renewed before copying it?  
You can overwrite cert files while they are loaded and everything will be fine. They will be reloaded after server restarts, or reloads.

Just copy them once every week to their destinations. Make a script or somekind of sync.

Best regards,  
Marijan

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 6, 2017, 11:48am UTC](https://community.letsencrypt.org/t/certbot-list-of-managed-certificates-after-renewals/31075/13 "2017-05-06T11:48:05Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
