# Migrating/renewing LetsEncrypt certificates between hosting providers

**URL:** <https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494>\
**Category:** Help\
**Created:** [March 7, 2024, 7:48pm UTC](https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494 "2024-03-07T19:48:45Z")\
**Posts on this page:** 6\
**Page:** 2

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [March 8, 2024, 2:42am UTC](https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494/21 "2024-03-08T02:42:57Z")

</div>

> [@custodian](#):
>
> Are you saying I can get new certs via certbot on the new VPS prior to making the DNS change for the associated domain?

No. Just that there was no need to change the DNS for those until you were sure your new system was working well for the other ones. In other words, you use the domains where you did have certs to prove your methods first.

Once you had your methods proven, move those over, change the DNS, and get the certs for them.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 8, 2024, 6:42am UTC](https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494/22 "2024-03-08T06:42:53Z")

</div>

You _can_ get a new cert _before_ the DNS change with the `--manual` plugin (as a temporary step) as mentioned before.

---

<div class="post-metadata">

**Author:** ![custodian](https://avatars.discourse-cdn.com/v4/letter/c/f9ae1b/32.png) [@custodian](https://community.letsencrypt.org/u/custodian)\
**Post date:** [March 8, 2024, 6:57am UTC](https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494/23 "2024-03-08T06:57:10Z")

</div>

Thanks Osiris. Hypothetically, if I were to create a new cert using --manual, then could I setup the renewal configuration manually also? Apart from version and cert paths, if I drop the following config into /etc/letsencrypt/renewal/gnmonlineseminars.com.conf, would that ensure that future renewals for the domain take place automatically as usual in spite of the --manual creation? If that's so, I might go this route, but I'd also need to know where to get the "...account\_id..." to put in place below.

[renewalparams]  
account = _account\_id_  
authenticator = webroot  
webroot-path = /path/to/gnmonlineseminars.com/public\_html  
agree-tos = true  
server = [https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 8, 2024, 7:15am UTC](https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494/24 "2024-03-08T07:15:04Z")

</div>

> [@custodian](#):
>
> if I were to create a new cert using --manual

Renewals are already included with all certs that are issued.  
[`certbot` will automatically setup a `cron` or `system-d timer` to check for cert renewals twice a day]

That said, if you did anything _manually_ during the issuance, the automated renewals will fail ☹

You should try to stay away from creating [or editing] any files managed by `certbot`.

I see that you aim to use `--webroot`, if that's the case, then you should use that instead of `--manual`.  
`--webroot` issued certs can be renewed just as easily as they are issued.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 8, 2024, 7:52am UTC](https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494/25 "2024-03-08T07:52:45Z")

</div>

> [@custodian](#):
>
> Hypothetically, if I were to create a new cert using --manual, then could I setup the renewal configuration manually also?

Hypothetically that's possible, yes.

> [@custodian](#):
>
> Apart from version and cert paths, if I drop the following config into /etc/letsencrypt/renewal/gnmonlineseminars.com.conf, would that ensure that future renewals for the domain take place automatically as usual in spite of the --manual creation?

Looks alright to me. Automated renewal would of course require a systemd timer/cronjob, but these are _usually_ installed automatically.

> [@custodian](#):
>
> If that's so, I might go this route, but I'd also need to know where to get the "...account\_id..." to put in place below.

You can find the account ID as a subfolder of the ACME server in `/etc/letsencrypt/accounts/` somewhere. But if you'd use the `--manual` plugin to bootstrap the new server, that value would already be filled out, just like `server` would be.

But as Rudy already mentions: manually editing these files is not recommended. I'd recommend using the `reconfigure` subcommand with Certbot 2.9.0 (or higher for future readers).

> [@rg305](#):
>
> `certbot` will automatically setup a `cron` or `system-d timer` to check for cert renewals twice a day

Not when Certbot is installed using `pip`, FYI.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 7, 2024, 7:52am UTC](https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494/26 "2024-04-07T07:52:50Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.

[Previous page](https://community.letsencrypt.org/t/migrating-renewing-letsencrypt-certificates-between-hosting-providers/214494.md?page=1)
