# Certbot reusing private key

**URL:** <https://community.letsencrypt.org/t/certbot-reusing-private-key/18711>\
**Category:** Help\
**Created:** [August 8, 2016, 12:22am UTC](https://community.letsencrypt.org/t/certbot-reusing-private-key/18711 "2016-08-08T00:22:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jtl](https://avatars.discourse-cdn.com/v4/letter/j/da6949/32.png) [@jtl](https://community.letsencrypt.org/u/jtl)\
**Post date:** [August 8, 2016, 12:22am UTC](https://community.letsencrypt.org/t/certbot-reusing-private-key/18711/1 "2016-08-08T00:22:58Z")

</div>

Please fill out the fields below so we can help you better.

My domain is: N/A

My operating system is (include version): Ubuntu 14.04 LTS

I can login to a root shell on my machine (yes or no, or I don’t know): Yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): No

Does Certbot have functionality to use private keys (for HPKP) or not currently. I know it supports the `--csr` option but that doesn’t allow the automated renewal functionality (which I require for my use-cases)

Thanks

---

<div class="post-metadata">

**Author:** ![cool110](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cool110/32/8583_2.png) [@cool110](https://community.letsencrypt.org/u/cool110)\
**Post date:** [August 8, 2016, 4:42am UTC](https://community.letsencrypt.org/t/certbot-reusing-private-key/18711/2 "2016-08-08T04:42:21Z")

</div>

No, the recommended way to use HPKP is to pin the root + backups

> [@HPKP best practices if you choose to implement](https://community.letsencrypt.org/t/hpkp-best-practices-if-you-choose-to-implement/4625):
>
> H…

---

<div class="post-metadata">

**Author:** ![jtl](https://avatars.discourse-cdn.com/v4/letter/j/da6949/32.png) [@jtl](https://community.letsencrypt.org/u/jtl)\
**Post date:** [August 8, 2016, 4:49am UTC](https://community.letsencrypt.org/t/certbot-reusing-private-key/18711/3 "2016-08-08T04:49:03Z")

</div>

True, but for my use case I already generated 10 keypairs which I pin with and I have two encrypted USB drives in two separate offline storage facilities contains backups of them.

In this way I am not stuck if a CA changed their intermediate or root without notice/goes under (It’s happened before _cough_ DigiNotar and Comodo UserTrust.

Ah well I’ll write my own Bash wrapper to handle post renewal actions with my own CSR. Would be great if the LetsEncrypt team integrated it with the renewal functionality.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 7, 2016, 4:49am UTC](https://community.letsencrypt.org/t/certbot-reusing-private-key/18711/4 "2016-09-07T04:49:26Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
