Certbot snap Error while renewing (OPENSSL_init_ssl)

Which snap installer package should I install to solve this problem?

Not sure if resorting to snap actually would fix this issue, I just wanted to state in general that using the operating systems package manager is not the recommended method of installing Certbot. I don't know of a solution to this threads issue unfortunately.

I also don't see an issue about this yet on GitHub · Where software is built. I would recommend someone having this problem to file an issue on the Github repository.

Yes, I realize now that I was using an unofficial installation package, but that allowed me to update the certificates. I uninstalled those packages, but the same error appears when I try to update.

A temporary fix:

mount --bind /usr/lib64/ossl-modules/ /snap/certbot/4325/usr/lib/x86_64-linux-gnu/ossl-modules/

Maybe that provides enough time for the maintainers to fix this

I confirm this bug too: Certbot halts on renew. I've filled the issue: Certbot halts while renewing because can't start Nginx: `/snap/certbot/4412/usr/lib/x86_64-linux-gnu/ossl-modules/fips.so`: No such file or directory error · Issue #10190 · certbot/certbot · GitHub

This command helped me. Thank you !

i was unable to reproduce this despite setting up multiple machines to try and do so. despite this, i believe i've fixed the problem and would love it if someone having this issue can help me test it

if you're still able to reproduce this problem, does it go away after running?

sudo snap refresh --channel=edge certbot

this command will update your certbot snap to follow our "edge" snap channel which is built nightly from our main branch. i recently pushed what i believe is a fix for this there

if after testing this you want to switch back to the default, stable channel you can run:

sudo snap refresh --channel=stable certbot

i currently plan to include the current fix in edge in the next stable release of certbot, but it'd be nice to know for sure that it works before pushing the change more widely

thanks for any support!

Hi @bmw , good afternoon. Thank you, I can confirm this works:

[ec2-user@ ~]$ sudo /usr/bin/certbot renew
Saving debug log to /var/log/letsencrypt/letsencrypt.log


Processing /etc/letsencrypt/renewal/REDACTED.conf


Certificate not yet due for renewal


The following certificates are not due for renewal yet:
/etc/letsencrypt/live/REDACTED/fullchain.pem expires on 2025-05-02 (skipped)
No renewals were attempted.


[ec2-user@ ~]$ sudo /usr/bin/certbot renew --force-renewal
Saving debug log to /var/log/letsencrypt/letsencrypt.log


Processing /etc/letsencrypt/renewal/REDACTED.conf


Error while running nginx -c /etc/nginx/nginx.conf -t.

nginx: [alert] OPENSSL_init_ssl(....)


All renewals failed. The following certificates could not be renewed:
/etc/letsencrypt/live/REDACTED/fullchain.pem (failure)


1 renew failure(s), 0 parse failure(s)
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
[ec2-user@ ~]$ sudo snap refresh --channel=edge certbot
certbot (edge) 4.0.0.dev0 from Certbot Project (certbot-eff✓) refreshed
[ec2-user@ ~]$ sudo /usr/bin/certbot renew --force-renewal
Saving debug log to /var/log/letsencrypt/letsencrypt.log


Processing /etc/letsencrypt/renewal/REDACTED.conf


Renewing an existing certificate for REDACTED
Reloading nginx server after certificate renewal


Congratulations, all renewals succeeded:
/etc/letsencrypt/live/REDACTED/fullchain.pem (success)


Please don't use --force-renewal for testing purposes, use --dry-run for that.

thanks so much @driade

i plan to push this fix out to all snap users on tuesday