# Lost private key

**URL:** <https://community.letsencrypt.org/t/lost-private-key/53560>\
**Category:** Help\
**Created:** [February 19, 2018, 9:53pm UTC](https://community.letsencrypt.org/t/lost-private-key/53560 "2018-02-19T21:53:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![der\_tom](https://avatars.discourse-cdn.com/v4/letter/d/e8c25b/32.png) [@der\_tom](https://community.letsencrypt.org/u/der_tom)\
**Post date:** [February 19, 2018, 9:53pm UTC](https://community.letsencrypt.org/t/lost-private-key/53560/1 "2018-02-19T21:53:19Z")

</div>

hi,

i have accidently deleted my /privkey.pem file.

how can i start over?  
thx

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [February 19, 2018, 9:57pm UTC](https://community.letsencrypt.org/t/lost-private-key/53560/2 "2018-02-19T21:57:47Z")

</div>

Hi @der_tom,

You can make an empty file to replace it (with `touch` or something), but if your web server was already configured to use it, the web server probably won’t be able to start up without a real key there. However, if this doesn’t prevent your web server from working in various ways (which depends on your configuration), you could then run `certbot renew --force-renewal` and get a new certificate with the same setup, which will then replace the old one with the missing private key.

If this isn’t an option, you should run `certbot certificates` to get the certificate name of the certificate with the missing private key, and `certbot delete --cert-name yourcertname.example.org` to delete it from your system. Also be sure that there are no references to it in your web server configuration. Then you can start the process from scratch.

Be aware of the rate limits:

> **[Rate Limits - Let's Encrypt - Free SSL/TLS Certificates](https://letsencrypt.org/docs/rate-limits/)**
>
> Last updated: January 4, 2018 | See all Documentation
> Let’s Encrypt provides rate limits to ensure fair usage by as many people as possible. We believe these rate limits are high enough to work for most people by default. We’ve also designed them so...

But if you’ve only issued one certificate, you’d be in no danger of hitting the rate limits by re-issuing it once.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [February 19, 2018, 9:58pm UTC](https://community.letsencrypt.org/t/lost-private-key/53560/3 "2018-02-19T21:58:58Z")

</div>

Actually, it occurs to me that there may be a better solution. Certbot makes backups of your private keys. In order to know how to use one to fix things, can you tell me the exact directory path of what you deleted?

---

<div class="post-metadata">

**Author:** ![der\_tom](https://avatars.discourse-cdn.com/v4/letter/d/e8c25b/32.png) [@der\_tom](https://community.letsencrypt.org/u/der_tom)\
**Post date:** [February 20, 2018, 2:19am UTC](https://community.letsencrypt.org/t/lost-private-key/53560/4 "2018-02-20T02:19:06Z")

</div>

hi seth,

you are right - it seems the folder “archive” contains all the files. one  
directory per domain with various timestamps. thing is: until today i used  
one certbot command to renew all 4 domains - today i have learned that it  
should be better to go a single route - one certbot for each  
domain…whats my best route?

how can i start from scratch and give each certbot its own webrootpath &  
yet have nginx pick only one private key ? if thats possibe…

thx

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [February 20, 2018, 4:18am UTC](https://community.letsencrypt.org/t/lost-private-key/53560/5 "2018-02-20T04:18:00Z")

</div>

Hi @der_tom,

If you want to recover your current configuration, you could recreate the symlink from `live` to `archive` — I can tell you how to do that if you’d like.

If you want to delete this, you can still use the `certbot delete` command that I mentioned.

There is no requirement to issue certificates with individual names separately. There are advantages and disadvantages to both styles. As you may have learned, each time you run Certbot it tries to get a new certificate, so if you do want four separate certificates, you would run it four times, while if you want a single certificate covering all of the domains, you would just run it once and specify all of the domains with `-d`. Again, both forms have advantages and disadvantages, which we can discuss in more detail if you’re interested.

Certbot doesn’t have convenient support for using a single private key for separate certificates (there are ways to do this with Certbot but they won’t work with automated renewal, because they require explicitly creating a Certificate Signing Request (CSR) file, and the resulting certificate won’t be stored in `/etc/letsencrypt` and renewed automatically the way that Certbot normally does). I’m not sure what the technical advantage in using the same private key for four different certificates would be; can you describe why you would want to do that?

---

<div class="post-metadata">

**Author:** ![der\_tom](https://avatars.discourse-cdn.com/v4/letter/d/e8c25b/32.png) [@der\_tom](https://community.letsencrypt.org/u/der_tom)\
**Post date:** [February 20, 2018, 2:33pm UTC](https://community.letsencrypt.org/t/lost-private-key/53560/6 "2018-02-20T14:33:17Z")

</div>

just dlchecked the folder archive - but the file i want is not there -  
privkey.pem

so next thign i did was i used certbot delete and went tru all domains.

now, doing a dry run works fine on the first domain - without redirecting  
the server to https. in order to do so i need to specify ssl\_certificate  
& ssl\_certificate\_key.

how do i go about now?

thx

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [February 20, 2018, 5:19pm UTC](https://community.letsencrypt.org/t/lost-private-key/53560/7 "2018-02-20T17:19:36Z")

</div>

There would have been _another_ backup of the private key that you could have used, but that’s OK!

The `ssl_certificate` should be `/etc/letsencrypt/example.com/live/fullchain.pem`, and the `ssl_certificate_key` should be `/etc/letsencrypt/example.com/live/privkey.pem`, after you’ve obtained the new certificate without `--dry-run`.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 22, 2018, 5:19pm UTC](https://community.letsencrypt.org/t/lost-private-key/53560/8 "2018-03-22T17:19:40Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
