# Complete no sudo version?

**URL:** https://community.letsencrypt.org/t/complete-no-sudo-version/4054
**Category:** Server
**Created:** [November 17, 2015, 11:46pm UTC](https://community.letsencrypt.org/t/complete-no-sudo-version/4054 "2015-11-17T23:46:33Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![ryan](https://avatars.discourse-cdn.com/v4/letter/r/a8b319/32.png) [@ryan](https://community.letsencrypt.org/u/ryan)
#### Post date: [November 17, 2015, 11:46pm UTC](https://community.letsencrypt.org/t/complete-no-sudo-version/4054/1 "2015-11-17T23:46:33Z")

</div>

Hey, so I am on a Dreamhost shared server, and as you probably know, shared hosting users don’t have sudo privileges, at least I don’t. Is there a way to use the Let’s Encrypt without sudo? Before you mention it, I know that there is: [https://github.com/diafygi/letsencrypt-nosudo](https://github.com/diafygi/letsencrypt-nosudo)

As the name implies, it doesn’t require sudo… but it does. Very deceptive. I know that this is a third party script, but is there a way to verify that you own the server even if you don’t have sudo privileges. I have seen CA’s have you create a file on the server that a bot reads the contents of to determine if you own the domain. Does Let’s Encrypt have something like that?

No matter how many times I beg, Dreamhost refuses to help me with this

In conclusion, is there a way to:

1. Run Let’s Encrypt Auto without Sudo
2. Run letsencrypt-nosudo without the LAST LITTLE SUDO COMMAND
3. Verify that you own the domain by having a script read a file off of your server

Also, VPS or Dedicated Servers are no option  
Thanks

---

<div class="post-metadata">

### Author: ![catdog2](https://avatars.discourse-cdn.com/v4/letter/c/e274bd/32.png) [@catdog2](https://community.letsencrypt.org/u/catdog2)
#### Post date: [November 18, 2015, 12:13am UTC](https://community.letsencrypt.org/t/complete-no-sudo-version/4054/2 "2015-11-18T00:13:15Z")

</div>

> [@ryan](#):
>
> Run letsencrypt-nosudo without the LAST LITTLE SUDO COMMAND

Are you able to configure the web server to do reverse proxying? Then you can run the command without sudo changing the port from 80 to something \>=1024

> [@LE client needs to bind to port 80, which I'm already using](https://community.letsencrypt.org/t/le-client-needs-to-bind-to-port-80-which-im-already-using/2739/9):
>
> J…

You can as a last resort also use the manual mode and run the LE client somewhere else.

---

<div class="post-metadata">

### Author: ![K.A.B](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@K.A.B](https://community.letsencrypt.org/u/K.A.B)
#### Post date: [November 18, 2015, 1:26am UTC](https://community.letsencrypt.org/t/complete-no-sudo-version/4054/3 "2015-11-18T01:26:33Z")

</div>

There is also the webroot method, which should work without root as well. That being said the client itself needs root to installed. I don’t know if you can work around that by calling `letsencrypt` directly instead of `letsencrypt-auto`

---

<div class="post-metadata">

### Author: ![ouroborus](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ouroborus/32/457_2.png) [@ouroborus](https://community.letsencrypt.org/u/ouroborus)
#### Post date: [November 22, 2015, 6:22am UTC](https://community.letsencrypt.org/t/complete-no-sudo-version/4054/4 "2015-11-22T06:22:34Z")

</div>

If you’re willing to set things up manually, while you currently need `sudo`, it doesn’t need to be on the web server. You could, for example, run a live CD and install and run letsencrypt on that.

For me, I did something like:  
`sudo letsencrypt -a manual --manual certonly`

It asks if you’re okay with having your IP address logged, if you agree with the terms of use, what your email address is, and what domains you want the certificate tied to.

It gives you some instructions telling you the location and content you need and how to verify it (and a list of commands to run on the server to achieve this if you don’t already have a server) and waits until you tell it you’ve done the setup. (Twice.)

I set up the file and the content myself. When I let it know I was ready, it notified letsencrypt to verify the url and content. Once that was successful, it wrote the certificate files, and exited. After that it was just a matter of installing the certificates myself. (My shared hosting service grants shell access but uses a web gui for installing certificates so if it weren’t for this method, I wouldn’t have been able to use letsencrypt.)

(For what it’s worth, I’m not sure if I need these files later for renewals or revocations.)

---

<div class="post-metadata">

### Author: ![thunderrabbit](https://avatars.discourse-cdn.com/v4/letter/t/dc4da7/32.png) [@thunderrabbit](https://community.letsencrypt.org/u/thunderrabbit)
#### Post date: [December 6, 2015, 3:53pm UTC](https://community.letsencrypt.org/t/complete-no-sudo-version/4054/5 "2015-12-06T15:53:43Z")

</div>

Based on @ouroborus notes, I wrote up instructions on how to do it on Dreamhost:

[https://new.robnugen.com/toots/use-letsencrypt-on-dreamhost/](https://new.robnugen.com/toots/use-letsencrypt-on-dreamhost/)

---

<div class="post-metadata">

### Author: ![ouroborus](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ouroborus/32/457_2.png) [@ouroborus](https://community.letsencrypt.org/u/ouroborus)
#### Post date: [December 7, 2015, 2:04am UTC](https://community.letsencrypt.org/t/complete-no-sudo-version/4054/6 "2015-12-07T02:04:55Z")

</div>

> [@thunderrabbit](#):
>
> Based on @ouroborus notes, I wrote up instructions on how to do it on Dreamhost:
> 
> [https://new.robnugen.com/toots/use-letsencrypt-on-dreamhost/](https://new.robnugen.com/toots/use-letsencrypt-on-dreamhost/)

I use DH as well. I used `fullchain.pem` instead of `cert.pem` and left the intermediate certificate blank.

Good write up, though.

---

<div class="post-metadata">

### Author: ![ryan](https://avatars.discourse-cdn.com/v4/letter/r/a8b319/32.png) [@ryan](https://community.letsencrypt.org/u/ryan)
#### Post date: [December 17, 2015, 11:53pm UTC](https://community.letsencrypt.org/t/complete-no-sudo-version/4054/7 "2015-12-17T23:53:35Z")

</div>

Worked perfectly! Thank you!
