# Installing letsencrypt

**URL:** <https://community.letsencrypt.org/t/installing-letsencrypt/7896>\
**Category:** Server\
**Created:** [December 29, 2015, 10:20am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896 "2015-12-29T10:20:10Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://community.letsencrypt.org/u/Hendrik)\
**Post date:** [December 29, 2015, 10:20am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/1 "2015-12-29T10:20:10Z")

</div>

Hi,

Before i already made the following post:

> [@/root/.local/share/letsencrypt/bin/pip: No such file or directory](https://community.letsencrypt.org/t/root-local-share-letsencrypt-bin-pip-no-such-file-or-directory/6631):
>
> H…

The problem was that i was running on CentOS version 5.5, so first i had to update CentOS on my server. Now i did that and i started again with everything.

Because i am pretty much a newbie with server side things, i followed the instructions from:

[https://raymii.org/s/articles/Lets\_Encrypt\_Directadmin.html](https://raymii.org/s/articles/Lets_Encrypt_Directadmin.html)

I did the following:

- Downloaded putty and made connection with the server as the root user.
- I checked the versions of CentOS and Python:

CentOS release 6.7 (Final)  
Python 2.6.6

- Git was already installed on the server, so i did not have to do that.
- I gave to following command with Putty:

git clone [GitHub - certbot/certbot: Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol.](https://github.com/letsencrypt/letsencrypt)

The response was:

* * *

git: /usr/local/lib/libz.so.1: no version information available (required by git)  
Initialized empty Git repository in /letsencrypt/.git/  
git-remote-https: /usr/local/lib/libz.so.1: no version information available (required by git-remote-https)  
git: /usr/local/lib/libz.so.1: no version information available (required by git)  
remote: Counting objects: 27171, done.  
git: /usr/local/lib/libz.so.1: no version information available (required by git)  
remote: Total 27171 (delta 0), reused 0 (delta 0), pack-reused 27171  
Receiving objects: 100% (27171/27171), 7.08 MiB | 2.76 MiB/s, done.  
Resolving deltas: 100% (19116/19116), done.

* * *

- I gave the following command with Putty:

cd letsencrypt

- I gave the following command with Putty:

./letsencrypt-auto --server [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory) certonly --agree-tos --email 'CONTACT@MYDOMAIN.NL' --webroot --webroot-path '/home/MYUSERNAME/domains/MYDOMAIN.NL/public\_html/' -d MYDOMAIN.NL -d www.MYDOMAIN.NL

The end of the response was:

* * *

Complete!  
WARNING: Python 2.6 support is very experimental at present...  
if you would like to work on improving it, please ensure you have backups  
and then run this script again with the --debug flag!

* * *

- So i runned it again with the --debug flag:

./letsencrypt-auto --server [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory) certonly --agree-tos --email 'CONTACT@MYDOMAIN.NL' --webroot --webroot-path '/home/MYUSERNAME/domains/MYDOMAIN.NL/public\_html/' -d MYDOMAIN.NL -d www.MYDOMAIN.NL --debug

The response was:

* * *

Bootstrapping dependencies for RedHat-based OSes...  
yum is /usr/bin/yum  
Loaded plugins: fastestmirror  
Setting up Install Process  
Loading mirror speeds from cached hostfile

- base: [mirror.denit.net](http://mirror.denit.net)
- extras: [mirror.denit.net](http://mirror.denit.net)
- updates: centos.mirror.triple-it.nl  
Package python-2.6.6-64.el6.x86\_64 already installed and latest version  
Package python-devel-2.6.6-64.el6.x86\_64 already installed and latest version  
No package python-virtualenv available.  
Nothing to do  
Loaded plugins: fastestmirror  
Setting up Install Process  
Loading mirror speeds from cached hostfile
- base: [mirror.denit.net](http://mirror.denit.net)
- extras: [mirror.denit.net](http://mirror.denit.net)
- updates: centos.mirror.triple-it.nl  
Package gcc-4.4.7-16.el6.x86\_64 already installed and latest version  
Package dialog-1.1-9.20080819.1.el6.x86\_64 already installed and latest version  
Package augeas-libs-1.0.0-10.el6.x86\_64 already installed and latest version  
Package openssl-devel-1.0.1e-42.el6\_7.1.x86\_64 already installed and latest version  
Package libffi-devel-3.0.5-3.2.el6.x86\_64 already installed and latest version  
Package redhat-rpm-config-9.0.3-44.el6.centos.noarch already installed and latest version  
Package ca-certificates-2015.2.4-65.0.1.el6\_6.noarch already installed and latest version  
Nothing to do  
Creating virtual environment...  
./letsencrypt-auto: line 167: virtualenv: command not found

* * *

If you take a loot at: [https://raymii.org/s/articles/Lets\_Encrypt\_Directadmin.html](https://raymii.org/s/articles/Lets_Encrypt_Directadmin.html)

Then they are saying that the response has to be something like:

"Congratulations! Your certificate and chain have been saved at /etc/letsencrypt/live/certificatemonitor.org/fullchain.pem. Your cert will expire on 2016-03-06. To obtain a new version of the certificate in the future, simply run Let's Encrypt again."

I also checked if the directory /etc/letsencrypt exists, but that's not the case:

[root@srv etc]# cd /  
[root@srv /]# cd etc  
[root@srv etc]# cd letsencrypt  
-bash: cd: letsencrypt: No such file or directory

Now finally the question:

What is going wrong? I followed all the steps exactly...

p.s. Probably the problem is: "No package python-virtualenv available.". And probably i have to install that package? How can i do that and is that indeed the problem?

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [December 29, 2015, 10:29am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/2 "2015-12-29T10:29:55Z")

</div>

> [@Hendrik](#):
>
> No package python-virtualenv available.

This is the interesting bit, I think. The docs state that the EPEL repository needs to be enabled on CentOS for letsencrypt to work. EPEL seems to include python-virtualenv. Try running `yum install epel-release` first and then run the `letsencrypt-auto` command again.

---

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://community.letsencrypt.org/u/Hendrik)\
**Post date:** [December 29, 2015, 10:52am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/3 "2015-12-29T10:52:18Z")

</div>

It’s weird, because i checked:

[https://letsencrypt.readthedocs.org/en/latest/intro.html](https://letsencrypt.readthedocs.org/en/latest/intro.html)

And i checked the “System Requirements” and there they are saying nothing about EPEL.

But i did what you said, but now the response contains the following:

* * *

Creating virtual environment…  
Updating letsencrypt and virtual environment dependencies…/root/.local/share/letsencrypt/lib/python2.6/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:90: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. For more information, see [https://urllib3.readthedocs.org/en/latest/security.html#insecureplatformwarning](https://urllib3.readthedocs.org/en/latest/security.html#insecureplatformwarning).  
InsecurePlatformWarning  
/root/.local/share/letsencrypt/lib/python2.6/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:90: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. For more information, see [https://urllib3.readthedocs.org/en/latest/security.html#insecureplatformwarning](https://urllib3.readthedocs.org/en/latest/security.html#insecureplatformwarning).  
InsecurePlatformWarning  
./root/.local/share/letsencrypt/lib/python2.6/site-packages/cryptography/ **init**.py:25: DeprecationWarning: Python 2.6 is no longer supported by the Python core team, please upgrade your Python.  
DeprecationWarning  
/root/.local/share/letsencrypt/lib/python2.6/site-packages/cryptography/ **init**.py:25: DeprecationWarning: Python 2.6 is no longer supported by the Python core team, please upgrade your Python.  
DeprecationWarning

Requesting root privileges to run with virtualenv: /root/.local/share/letsencrypt/bin/letsencrypt --server [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory) certonly --agree-tos --email [CONTACT@MYDOMAIN.NL](mailto:CONTACT@MYDOMAIN.NL) --webroot --webroot-path /home/MYUSERNAME/domains/MYDOMAIN.NL/public\_html/ -d [MYDOMAIN.NL](http://MYDOMAIN.NL) -d [www.MYDOMAIN.NL](http://www.MYDOMAIN.NL) --debug  
/root/.local/share/letsencrypt/lib/python2.6/site-packages/cryptography/ **init**.py:25: DeprecationWarning: Python 2.6 is no longer supported by the Python core team, please upgrade your Python.  
DeprecationWarning

* * *

This will not be a problem later on? And the Python core team is saying that i have to update the Python version (HOW?), but letsencrypt is saying that 2.6 is okay in their “System Requirements”.

---

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://community.letsencrypt.org/u/Hendrik)\
**Post date:** [December 29, 2015, 10:57am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/4 "2015-12-29T10:57:46Z")

</div>

And one more question…the mailaddress is from a different domain then the certificate is on, but that’s no problem i think, right?

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [December 29, 2015, 11:08am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/5 "2015-12-29T11:08:19Z")

</div>

> [@Hendrik](#):
>
> It's weird, because i checked:
> 
> [INTRODUCTION — letsencrypt latest documentation](https://letsencrypt.readthedocs.org/en/latest/intro.html)
> 
> And i checked the "System Requirements" and there they are saying nothing about EPEL.

The documentation is indeed a bit redundant here, and not really in sync with the [more detailed installation guide](https://letsencrypt.readthedocs.org/en/latest/using.html#installation) where this is mentioned.

> [@Hendrik](#):
>
> This will not be a problem later on? And the Python core team is saying that i have to update the Python version (HOW?), but letsencrypt is saying that 2.6 is okay in their "System Requirements".

It's fine, CentOS maintains older versions of packages they ship as long as the CentOS version is still supported. I'm not familiar enough with CentOS to say whether upgrading python is a good idea (it's generally a bit of a hassle on debian/ubuntu), but as long as you manage to get your certificates, there shouldn't be any issues in the future (unless letsencrypt drops 2.6 support completely).

> [@Hendrik](#):
>
> And one more question...the mailaddress is from a different domain then the certificate is on, but that's no problem i think, right?

That's okay, the email will only be used for renewal reminders (and in the future possibly account recovery if you lose the private key).

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [December 29, 2015, 11:52am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/6 "2015-12-29T11:52:22Z")

</div>

> [@pfg](#):
>
> (…) whether upgrading python is a good idea (…)

The latest Python 2.6 is from [2013](https://www.python.org/download/releases/2.6.9/) and was officially retired after that (security) update, so upgrading to 2.7 isn't such a bad thing in any case I recon. Two years without any security update, not such a good idea.

I've found [a guide](https://github.com/h2oai/h2o-2/wiki/Installing-python-2.7-on-centos-6.3.-Follow-this-sequence-exactly-for-centos-machine-only) online with a warning: "if you install python 2.7 in any way other than the following you will destroy the system and make yum inoperable", but as long as you follow that guide, you should be fine I guess 😛 (no guarantees on my end ;))

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [December 29, 2015, 11:53am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/7 "2015-12-29T11:53:31Z")

</div>

> [@Osiris](#):
>
> The latest Python 2.6 is from 2013 and was officially retired after that (security) update, so upgrading to 2.7 isn't such a bad thing in any case I recon. Two years without any security update, not such a good idea.

My point is that CentOS still supports it, which means backporting security patches and such. Sure, it's still a good idea.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [December 29, 2015, 11:59am UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/8 "2015-12-29T11:59:49Z")

</div>

They do? Ugh, what a hassle… Even Debian oldstable (wheezy) has Python 2.7 😛

Apparently, [CentOS 6.7 comes with Python 2.6 by default](http://mirror.centos.org/centos/6.7/os/x86_64/Packages/). Only since [CentOS 7](http://mirror.centos.org/centos/7/os/x86_64/Packages/) they provide Python 2.7.

---

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://community.letsencrypt.org/u/Hendrik)\
**Post date:** [December 29, 2015, 12:06pm UTC](https://community.letsencrypt.org/t/installing-letsencrypt/7896/9 "2015-12-29T12:06:11Z")

</div>

Thank you very much! I think i am almost there. Now i already have https on my domain and i tested it with:

[https://www.ssllabs.com/ssltest/analyze.html](https://www.ssllabs.com/ssltest/analyze.html)

I got an “A”, so that’s nice! To be sure i am gonna ask my host if it’s safe to install Python 2.7 on the server.

I still have some last questions:

— 1. Renewal —

On:

[https://letsencrypt.org/howitworks/](https://letsencrypt.org/howitworks/)

They are saying:

“To renew a certificate, simply run letsencrypt again providing the same values when prompted. Let’s Encrypt is working hard to fully automate this process and we apologize for the inconvenience until this functionality is ready.”

But on:

[https://letsencrypt.readthedocs.org/en/latest/using.html#renewal](https://letsencrypt.readthedocs.org/en/latest/using.html#renewal)

There they are already giving some more options, but totally not with a clear explanation for newbies ;).

The thing is that i followed:

[https://raymii.org/s/articles/Lets\_Encrypt\_Directadmin.html](https://raymii.org/s/articles/Lets_Encrypt_Directadmin.html)

I copy / paste the content of the certificate files in Directadmin. But in the “tutorial” they are saying:

Installing the certificates -\> “As we can see they symlinked the files there. If you configure your own webserver manually, you can give these files as the location in your apace or nginx config. When you renew the certificate later on, you don’t have to update the webserver config, just a reload/restart.”

So for easy renawel i think i have to do that, right?

With Directadmin i can change “Custom HTTPD Configurations” for a specific domain. For example i can change:

SSLCertificateFile /usr/local/directadmin/data/users/MYUSERNAME/domains/MYDOMAIN.nl.cert  
SSLCertificateKeyFile /usr/local/directadmin/data/users/MYUSERNAME/domains/MYDOMAIN.nl.key  
SSLCACertificateFile /usr/local/directadmin/data/users/MYUSERNAME/domains/MYDOMAIN.nl.cacert

But to what i have to change it? Letsencrypt is makeing 4 files: privkey.pem, fullchain.pem, chain.pem, cert.pem, but there are only 3 files: MYDOMAIN.nl.cert, MYDOMAIN.nl.key, MYDOMAIN.nl.cacert

And what else i have to do to arrange that the certificates will renew automatically?

— 2. More domains —  
I have a server with one ipaddress. On a couple of domains on the server i want to work with https.

First question: Imagine that i have a website and if a visitor is making an account on that website, they will get their own url, for example: [newuser.domain.nl](http://newuser.domain.nl)  
Now i did:

./letsencrypt-auto --server [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory) certonly --agree-tos --email ‘CONTACT@MYDOMAIN.NL’ --webroot --webroot-path ‘/home/MYUSERNAME/domains/MYDOMAIN.NL/public\_html/’ -d [MYDOMAIN.NL](http://MYDOMAIN.NL) -d [www.MYDOMAIN.NL](http://www.MYDOMAIN.NL) --debug

But actually with subdomains Letsencrypt is saying that i have to put: “-d [newuser.MYDOMAIN.NL](http://newuser.MYDOMAIN.NL)” for every subdomain, right? But the subdomains are dynamically made, so how i have to deal with that? Is there something like \*.mydomain.nl (wildcard)?

Second question:

If i want to install https on other domains on the server (same ip). Can i just do:

./letsencrypt-auto --server [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory) certonly --agree-tos --email ‘CONTACT@MYDOMAIN.NL’ --webroot --webroot-path ‘/home/OTHERUSERNAME/domains/OTHERDOMAIN.NL/public\_html/’ -d [OTHERDOMAIN.NL](http://OTHERDOMAIN.NL) -d [www.OTHERDOMAIN.NL](http://www.OTHERDOMAIN.NL) --debug

I changed MYDOMAIN to OTHERDOMAIN.

Is that right or is it not that simple? And if not, how do i have to deal with that?
