My web server is (include version): "Apache/2.4.57 (Debian)"
The operating system my web server runs on is (include version):
Rpi running debian:
lsb_release -a
No LSB modules are available.
Distributor ID: Debian
Description: Debian GNU/Linux 12 (bookworm)
Release: 12
Codename: bookworm
My hosting provider, if applicable, is:
I can login to a root shell on my machine (yes or no, or I don't know): yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): certbot 2.1.0
Hi
Cloud server running at "paritsu.kenyoh.com". Certbot indicating two different certificates. Don't know how this happened. One of them has been renewed some days ago, the second one not beeing renewed for unknown reason. Can one of them be removed without being feared to miss out access to the site and if yes, how?
Because the second certificate only covers paritsu.kenyoh.com.
If you don't need a certificate for the "apex" domain, then you can delete the certificate expiring in 23 days. Or you can leave it alone, it's not renewing and should not be a problem. If you need a certificate for kenyoh.com, though, you should get one.
Your kenyoh.com domain no longer has an A record in the DNS. No one on the public internet can find you by that name. This is probably also the reason your cert with both names failed to renew.
Your Apache server is using that older cert with both names. So, do not delete that cert before deciding how to proceed.
If you don't need to use the kenyoh.com name anymore you could change Apache to use the newer cert. After Apache is switched you could then delete the older one.
But, you have a long history of using both names so it seems you should fix the problem with kenyoh.com. Is that what you want to do? If so, you need to put the A record back in the DNS and then try
But actually because the "Type RSA" certificate is working for both domains, the "Type ECDSA" certificate could be deleted, right?
As being an absolutely noob with this stuff, i'm feared to screw things up to being unusable but would however like to clean up a little bit this setting.
Yes, I think so but only you know for sure. Your Apache looks to only be using the RSA cert with both names. The ECDSA cert only has the one domain name so unless you are using it for some other service it is not active and could be deleted like: