# Certbot renew hook not working

**URL:** <https://community.letsencrypt.org/t/certbot-renew-hook-not-working/160160>\
**Category:** Help\
**Created:** [September 21, 2021, 1:43am UTC](https://community.letsencrypt.org/t/certbot-renew-hook-not-working/160160 "2021-09-21T01:43:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![fyellin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/fyellin/32/49494_2.png) [@fyellin](https://community.letsencrypt.org/u/fyellin)\
**Post date:** [September 21, 2021, 1:43am UTC](https://community.letsencrypt.org/t/certbot-renew-hook-not-working/160160/1 "2021-09-21T01:43:44Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:  
[cirs.forward-scatter.com](http://cirs.forward-scatter.com)

I ran this command:  
certbot --renew (via cron job)

It produced this output:

```nohighlight
2021-09-20 04:33:12,842:DEBUG:certbot._internal.storage:Writing new private key to /etc/letsencrypt/archive/cirs.forward-scatter.com/privkey6.pem.
2021-09-20 04:33:12,842:DEBUG:certbot._internal.storage:Writing certificate to /etc/letsencrypt/archive/cirs.forward-scatter.com/cert6.pem.
2021-09-20 04:33:12,843:DEBUG:certbot._internal.storage:Writing chain to /etc/letsencrypt/archive/cirs.forward-scatter.com/chain6.pem.
2021-09-20 04:33:12,843:DEBUG:certbot._internal.storage:Writing full chain to /etc/letsencrypt/archive/cirs.forward-scatter.com/fullchain6.pem.
2021-09-20 04:33:12,861:DEBUG:certbot._internal.storage:Writing new config /etc/letsencrypt/renewal/cirs.forward-scatter.com.conf.new.
2021-09-20 04:33:12,866:INFO:certbot.compat.misc:Running deploy-hook command: /etc/letsencrypt/renewal-hooks/deploy/reload_apache.sh
2021-09-20 04:33:12,891:DEBUG:certbot.display.util:Notifying user: new certificate deployed without reload, fullchain is
/etc/letsencrypt/live/cirs.forward-scatter.com/fullchain.pem
2021-09-20 04:33:12,894:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2021-09-20 04:33:12,894:DEBUG:certbot.display.util:Notifying user:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2021-09-20 04:33:12,894:DEBUG:certbot.display.util:Notifying user: Congratulations, all renewals succeeded:
2021-09-20 04:33:12,894:DEBUG:certbot.display.util:Notifying user: /etc/letsencrypt/live/cirs.forward-scatter.com/fullchain.pem (success)
2021-09-20 04:33:12,894:DEBUG:certbot.display.util:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2021-09-20 04:33:12,894:DEBUG:certbot._internal.renewal:no renewal failures

```

My web server is (include version):  
Apache/2.4.46

The operating system my web server runs on is (include version):  
MacOs 11.4

My hosting provider, if applicable, is:  
None

I can login to a root shell on my machine (yes or no, or I don't know):  
yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):  
no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):  
1.14.0

After creating my certificates just fine, the log above has:  
Running deploy-hook command: /etc/letsencrypt/renewal-hooks/deploy/reload\_apache.sh

The contents of this file are:  
#!/bin/sh  
apachectl graceful

So I would think my apache has been gracefully restarted and that newer pages would have the updated credentials. However visiting the web site, I'm still seeing the certificate that is about to expire in three weeks.

If I run the deploy/reload\_apache.sh by hand (which I just did), it works fine. If I renew my certificate by using a --force-renewal, it works fine. It only fails when the certificate is renewed as part of a cron job.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 21, 2021, 3:33am UTC](https://community.letsencrypt.org/t/certbot-renew-hook-not-working/160160/2 "2021-09-21T03:33:58Z")

</div>

> [@fyellin](#):
>
> apachectl graceful

Might not do what you would be expecting.  
Their documentation shows:  
`apachectl -k graceful`  
See: [Stopping and Restarting Apache HTTP Server - Apache HTTP Server Version 2.4](https://httpd.apache.org/docs/2.4/stopping.html#page-header)

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [September 21, 2021, 3:46am UTC](https://community.letsencrypt.org/t/certbot-renew-hook-not-working/160160/3 "2021-09-21T03:46:15Z")

</div>

> [@fyellin](#):
>
> It only fails when the certificate is renewed as part of a cron job.

Symptoms like this make me immediately suspect `$PATH` problems.

Process trees which are started by `cron` (such as `cron`→`certbot`→`reload_apache.sh`) often have a more basic `$PATH` environment variable than e.g. the `$PATH` you see in your terminal.

If your shell script calls programs without using their absolute path, there's a chance that they won't run properly when invoked by the cron daemon.

I'm not a macOS user so I don't know what the default `$PATH` is in its crontab, but a fix you could try is to update your deploy hook to use absolute paths for all the programs it invokes, and additionally check the `PATH=` line in your crontab.

---

<div class="post-metadata">

**Author:** ![fyellin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/fyellin/32/49494_2.png) [@fyellin](https://community.letsencrypt.org/u/fyellin)\
**Post date:** [September 21, 2021, 5:01am UTC](https://community.letsencrypt.org/t/certbot-renew-hook-not-working/160160/4 "2021-09-21T05:01:40Z")

</div>

Excellent idea. Unfortunately I won’t find out if this fixes the problem for another two months.

---

<div class="post-metadata">

**Author:** ![fyellin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/fyellin/32/49494_2.png) [@fyellin](https://community.letsencrypt.org/u/fyellin)\
**Post date:** [September 22, 2021, 2:57am UTC](https://community.letsencrypt.org/t/certbot-renew-hook-not-working/160160/5 "2021-09-22T02:57:11Z")

</div>

I also noticed that a different launchctl plist includes the following lines:

```nohighlight
	<key>EnvironmentVariables</key>
	<dict>
		<key>PATH</key>
		<string>/usr/local/bin:/usr/local/sbin:/usr/bin:/bin:/usr/sbin:/sbin</string>
	</dict>

```

This adds to the likelihood that you are right. Programs are run without a proper `PATH` in their environment unless one is set explicitly.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 22, 2021, 2:57am UTC](https://community.letsencrypt.org/t/certbot-renew-hook-not-working/160160/6 "2021-10-22T02:57:49Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
