# Making certbot edit its own config files?

**URL:** <https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310>\
**Category:** Help\
**Created:** [April 3, 2020, 12:50pm UTC](https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310 "2020-04-03T12:50:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 3, 2020, 12:50pm UTC](https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310/1 "2020-04-03T12:50:40Z")

</div>

Let’s say I got a certificate using certbot and I forgot to include a `--deploy-hook`, or I want to change what authenticator plugin to use.

Can I use a command like

```nohighlight
certbot renew [--cert-name example.com] {whatever I want to change}

```

and expect certbot to save its own config without me needing to mess with editing `/etc/letsencrypt/renewal/example.com.conf`?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [April 3, 2020, 1:01pm UTC](https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310/2 "2020-04-03T13:01:24Z")

</div>

As far as I know, this is the case. Options which would be saved to the renewal configuration file on the first run, should also be saved when using `renew`. But I stand corrected if I’m wrong.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 4, 2020, 11:07am UTC](https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310/3 "2020-04-04T11:07:06Z")

</div>

I tried doing so(1) with a certificate that doesn’t need renewing and it didn’t edit the config file.

(1): `certbot renew --cert-name 128.qualcuno.xyz --deploy-hook "echo puppa"`

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [April 4, 2020, 11:15am UTC](https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310/4 "2020-04-04T11:15:13Z")

</div>

If `--dry-run` is included, it won’t update the config. You have to force a live renewal in order to update the config file. It’s one of the more irritating aspects of Certbot.

Did you omit `--dry-run` from your example command?

Anyway, I just tried it out and it seems to work.

After first issuance:

```
$ cat /etc/letsencrypt/renewal/3e2113e8.ngrok.io.conf
# renew_before_expiry = 30 days
version = 1.3.0
archive_dir = /etc/letsencrypt/archive/3e2113e8.ngrok.io
cert = /etc/letsencrypt/live/3e2113e8.ngrok.io/cert.pem
privkey = /etc/letsencrypt/live/3e2113e8.ngrok.io/privkey.pem
chain = /etc/letsencrypt/live/3e2113e8.ngrok.io/chain.pem
fullchain = /etc/letsencrypt/live/3e2113e8.ngrok.io/fullchain.pem

# Options used in the renewal process
[renewalparams]
authenticator = standalone
account = d9abe02fd65c89a22205ea9c1b980e05
http01_port = 8123
server = https://acme-staging-v02.api.letsencrypt.org/directory

```

then:

```
$ sudo certbot-auto certonly --standalone --http-01-port 8123 -d 3e2113e8.ngrok.io --staging --deploy-hook "/bin/true" --force-renewal

```

and the hook was added to the config:

```
$ cat /etc/letsencrypt/renewal/3e2113e8.ngrok.io.conf
# renew_before_expiry = 30 days
version = 1.3.0
archive_dir = /etc/letsencrypt/archive/3e2113e8.ngrok.io
cert = /etc/letsencrypt/live/3e2113e8.ngrok.io/cert.pem
privkey = /etc/letsencrypt/live/3e2113e8.ngrok.io/privkey.pem
chain = /etc/letsencrypt/live/3e2113e8.ngrok.io/chain.pem
fullchain = /etc/letsencrypt/live/3e2113e8.ngrok.io/fullchain.pem

# Options used in the renewal process
[renewalparams]
authenticator = standalone
account = d9abe02fd65c89a22205ea9c1b980e05
http01_port = 8123
server = https://acme-staging-v02.api.letsencrypt.org/directory
renew_hook = /bin/true
```

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 4, 2020, 11:17am UTC](https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310/5 "2020-04-04T11:17:00Z")

</div>

> [@\_az](#):
>
> Did you omit `--dry-run` from your example command?

Yes, but the renewal didn't happen because the cert is not expiring.

I guess it's time for a feature request, there's no reason to `--force-renewal` to update the configuration.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [April 4, 2020, 11:18am UTC](https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310/6 "2020-04-04T11:18:20Z")

</div>

Here’s an open one to add a vote to: [https://github.com/certbot/certbot/issues/5828](https://github.com/certbot/certbot/issues/5828)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 4, 2020, 11:18am UTC](https://community.letsencrypt.org/t/making-certbot-edit-its-own-config-files/118310/7 "2020-05-04T11:18:20Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
