# Modify a certificate

**URL:** <https://community.letsencrypt.org/t/modify-a-certificate/131220>\
**Category:** Help\
**Created:** [August 16, 2020, 4:02pm UTC](https://community.letsencrypt.org/t/modify-a-certificate/131220 "2020-08-16T16:02:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![arschulte](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@arschulte](https://community.letsencrypt.org/u/arschulte)\
**Post date:** [August 16, 2020, 4:02pm UTC](https://community.letsencrypt.org/t/modify-a-certificate/131220/1 "2020-08-16T16:02:53Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [www.lanasacoaching.com](http://www.lanasacoaching.com)

I ran this command:  
sudo certbot --apache -d [lanasacoaching.com](http://lanasacoaching.com)  
It produced this output:

My web server is (include version):  
I am not sure - I am using wordpress so I think it is apache  
The operating system my web server runs on is (include version):  
ubuntu 16.04.3  
My hosting provider, if applicable, is:  
digital ocean  
I can login to a root shell on my machine (yes or no, or I don’t know):  
yes  
I’m using a control panel to manage my site (no, or provide the name and version of the control panel):  
no  
The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot): 0.31.0

I am a relatively inexperienced Linux administrator and I am using Certbot for the first time. I mistakenly chose not to redirect all http to https when I created the certificate and now wish to do that. I have searched through all the topics here and either I’m not searching well enough or no one has been this dumb before. Is there a way to modify/replace the certificate to eliminate http and redirect everything to https?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [August 16, 2020, 4:14pm UTC](https://community.letsencrypt.org/t/modify-a-certificate/131220/2 "2020-08-16T16:14:43Z")

</div>

> [@arschulte](#):
>
> Is there a way to modify/replace the certificate to eliminate http and redirect everything to https?

That's not a certificate thing, but a feature of certbot. If you run the exact same certbot command as you've used before, certbot will recognise the previous issued certificate and will ask you if you'd like a new one issued (which isn't necessary) or if you'd like to reinstall the existing cert. Choose the latter. As far as I know, certbot _should_ ask you again if you'd like a redirect when installing the cert. Choose "yes" this time.

By the way, you might check your Wordpress Admin first: it has a setting for the URL used. Perhaps also something about HTTPS. This URL setting in Wordpress should contain `https://`. This _might_ also be enough without using certbot for the redirect. It might also be that if you set the redirect with certbot _without_ having the proper HTTPS URL set in Wordpress, your site might become inoperable. So please also check your Wordpress admin.

---

<div class="post-metadata">

**Author:** ![arschulte](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@arschulte](https://community.letsencrypt.org/u/arschulte)\
**Post date:** [August 16, 2020, 4:19pm UTC](https://community.letsencrypt.org/t/modify-a-certificate/131220/3 "2020-08-16T16:19:42Z")

</div>

Thank you for the super fast response. If I use [https://www.lanasacoaching.com](https://www.lanasacoaching.com) the website behaves correctly. And rerunning the command makes sense, I just am very new to Certbot and SSL so I wasn’t sure about the effect of doing that  
. Btw - should I have certificates for both [lanasacoaching.com](http://lanasacoaching.com) and [www.lanasacoaching.com](http://www.lanasacoaching.com)? And would that mean that I have to use the --expand option to add [www.lanasacoaching.com](http://www.lanasacoaching.com) to the original certificate?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [August 16, 2020, 4:34pm UTC](https://community.letsencrypt.org/t/modify-a-certificate/131220/4 "2020-08-16T16:34:23Z")

</div>

> [@arschulte](#):
>
> Btw - should I have certificates for both [lanasacoaching.com](http://lanasacoaching.com) and [www.lanasacoaching.com](http://www.lanasacoaching.com)?

It's probably the best way to include both hostnames in the same certificate. You can re-run certbot with two `-d` options, one for each hostname. Certbot should ask you if you'd like to expand the existing certificate. You want that, so choose Yes.

> [@arschulte](#):
>
> And would that mean that I have to use the --expand option to add [www.lanasacoaching.com](http://www.lanasacoaching.com) to the original certificate?

`--expand` is also a good option so certbot knows what to do, yes. That way it doesn't have to ask you. But even with `--expand`, you should add _both_ hostnames on the command line, not just the hostname you'd like to add.

---

<div class="post-metadata">

**Author:** ![arschulte](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@arschulte](https://community.letsencrypt.org/u/arschulte)\
**Post date:** [August 16, 2020, 4:36pm UTC](https://community.letsencrypt.org/t/modify-a-certificate/131220/5 "2020-08-16T16:36:50Z")

</div>

This is really helpful, thank you.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 15, 2020, 4:36pm UTC](https://community.letsencrypt.org/t/modify-a-certificate/131220/6 "2020-09-15T16:36:51Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
