# Problem with Certbot renew

**URL:** https://community.letsencrypt.org/t/problem-with-certbot-renew/136830
**Category:** Help
**Created:** [October 26, 2020, 8:27am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830 "2020-10-26T08:27:44Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Joshua](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Joshua](https://community.letsencrypt.org/u/Joshua)
#### Post date: [October 26, 2020, 8:27am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/1 "2020-10-26T08:27:44Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [www.gemeinde-trierweiler.de](http://www.gemeinde-trierweiler.de)

I ran this command: certbot certonly [www.gemeinde-trierweiler.de](http://www.gemeinde-trierweiler.de) / certbot certonly [gemeinde-trierweiler.de](http://gemeinde-trierweiler.de)

It produced this output: Congratulations! Your Certificate has been renewed

My web server is (include version):

The operating system my web server runs on is (include version): Debian GNU/Linux 5

My hosting provider, if applicable, is: [strato.de](http://strato.de)

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): certbot 0.31.0

--

So my problem is that if I run certbot certonly [gemeinde-trierweiler.de](http://gemeinde-trierweiler.de) he gives me a positive output that my certficate has been successfully renewed, but if I visit the site, there's still the old certificate. Maybe I'm doing something really wrong. Certbot saves the certficate in a specific path, yet I don't know anymore what to do else. Thank you for your help

---

<div class="post-metadata">

### Author: ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)
#### Post date: [October 26, 2020, 8:31am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/2 "2020-10-26T08:31:24Z")

</div>

Hi @Joshua

> [@Joshua](#):
>
> certbot certonly

certonly doesn't install and restart your webserver.

Did you restart your webserver?

---

<div class="post-metadata">

### Author: ![Joshua](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Joshua](https://community.letsencrypt.org/u/Joshua)
#### Post date: [October 26, 2020, 8:40am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/3 "2020-10-26T08:40:42Z")

</div>

Tried that aswell already, I tried something else now... I just selected the temporary webserver option, let me restart it real quick again ...

Sorry, I am kind of new to certbot and stuff.. 🙂

Thank you for your reply!

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 8:46am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/4 "2020-10-26T08:46:50Z")

</div>

Welcome to the Let's Encrypt Community 🙂

You've already successfully acquired a certificate, so acquiring another one a different way will not help.

We need to fix your installation of the certificate.

* * *

**Complete Certificate History**

 ![Screenshot_20201026-024455_Samsung Internet](https://global.discourse-cdn.com/letsencrypt/original/3X/9/7/9772f51d4c48ea8f30e2a0db01ed1993630bd532.jpeg)

> **[crt.sh | gemeinde-trierweiler.de](https://crt.sh/?Identity=gemeinde-trierweiler.de&deduplicate=Y)**

---

<div class="post-metadata">

### Author: ![Joshua](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Joshua](https://community.letsencrypt.org/u/Joshua)
#### Post date: [October 26, 2020, 8:53am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/5 "2020-10-26T08:53:49Z")

</div>

Thank you very much!

How can we fix the certificate installation?

Thank you so much for your help. 🙂

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 8:54am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/6 "2020-10-26T08:54:12Z")

</div>

Please try using this command:  
`certbot run --apache -d "www.gemeinde-trierweiler.de,gemeinde-trierweiler.de" --keep-until-expiring`

Note: Your most recent certificate included [www.gemeinde-trierweiler.de](http://www.gemeinde-trierweiler.de/), but did **not** include [gemeinde-trierweiler.de](http://gemeinde-trierweiler.de/), which may cause you problems. We can fix that too.

---

<div class="post-metadata">

### Author: ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)
#### Post date: [October 26, 2020, 9:03am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/7 "2020-10-26T09:03:00Z")

</div>

Now checked your domain - [https://check-your-website.server-daten.de/?q=gemeinde-trierweiler.de](https://check-your-website.server-daten.de/?q=gemeinde-trierweiler.de)

You have created one correct certificate:

| Issuer | not before | not after | Domain names | LE-Duplicate | next LE |
| --- | --- | --- | --- | --- | --- |
| Let's Encrypt Authority X3 | 2020-10-20 | 2021-01-18 | [gemeinde-trierweiler.de](http://gemeinde-trierweiler.de), [www.gemeinde-trierweiler.de](http://www.gemeinde-trierweiler.de) - 2 entries | duplicate nr. 1 | |
| Let's Encrypt Authority X3 | 2020-10-06 | 2021-01-04 | [gemeinde-trierweiler.de](http://gemeinde-trierweiler.de) - 1 entries | | |

That from 2020-10-20 is good.

But it's not used, so Certbot doesn't understand your configuration. And your configuration (see your redirects) looks inconsistent.

What says

```auto
apachectl -S
certbot certificates

```

A port 80 vHost with both domain names is required, so Certbot can use that as template to create the port 443 vHost.

PS: It's **wrong** to create a new certificate if the certificate already exists. There is a rate limit. So don't create a new certificate if you have already one created.

---

<div class="post-metadata">

### Author: ![Joshua](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Joshua](https://community.letsencrypt.org/u/Joshua)
#### Post date: [October 26, 2020, 9:07am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/8 "2020-10-26T09:07:25Z")

</div>

Alright, I did what you told me to do.

Got the same return now: Congratulations! Your certificate and chain have been saved at: [...]  
Your key file has been saved at [...]  
Your cert will expire on 2021-01-18. [...]

---

<div class="post-metadata">

### Author: ![Joshua](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Joshua](https://community.letsencrypt.org/u/Joshua)
#### Post date: [October 26, 2020, 9:08am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/9 "2020-10-26T09:08:36Z")

</div>

Thank you very much!

Yeah, I thought so. I mean I've seen the .pem file aswell on the linux server itself but I just can't figure out how to install it or how to tell my webserver to use this certificate ...

Thank you

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 9:09am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/10 "2020-10-26T09:09:30Z")

</div>

@JuergenAuer

> [@JuergenAuer](#):
>
> That from 2020-10-20 is good.

I agree. I was hoping that the command I gave Joshua would set the live symlink to that certificate instead of the newer one that does not include [gemeinde-trierweiler.de](http://gemeinde-trierweiler.de).

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 9:10am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/11 "2020-10-26T09:10:52Z")

</div>

We're there! (Your certificate is now installed correctly.) 🙂

🥳

 ![Screenshot_20201026-031033_Samsung Internet](https://global.discourse-cdn.com/letsencrypt/original/3X/6/c/6ceff137e3c52505fe8560539412e4f971610403.jpeg)

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 9:13am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/12 "2020-10-26T09:13:23Z")

</div>

Now you just need to fix your redirects...

The 302 here should be a 301 to [https://gemeinde-trierweiler.de](https://gemeinde-trierweiler.de) :

![Screenshot_20201026-024135_Samsung Internet](https://global.discourse-cdn.com/letsencrypt/original/3X/5/a/5aba7a28e8fce68e4d1f6d9c9628f689491a119f.jpeg)

The 302 here should be removed entirely:

![Screenshot_20201026-024045_Samsung Internet](https://global.discourse-cdn.com/letsencrypt/original/3X/4/c/4cd08867c328a4483322ee7021842c20d7ca1b91.jpeg)

You also want to make sure that [http://www.gemeinde-trierweiler.de](http://www.gemeinde-trierweiler.de) has a single 301 redirect to [https://www.gemeinde-trierweiler.de](https://www.gemeinde-trierweiler.de).

In short (all 301):

- [http://www.gemeinde-trierweiler.de](http://www.gemeinde-trierweiler.de) -\> [https://www.gemeinde-trierweiler.de](https://www.gemeinde-trierweiler.de)
- [http://gemeinde-trierweiler.de](http://gemeinde-trierweiler.de) -\> [https://gemeinde-trierweiler.de](https://gemeinde-trierweiler.de)
- [https://gemeinde-trierweiler.de](https://gemeinde-trierweiler.de) -\> [https://www.gemeinde-trierweiler.de](https://www.gemeinde-trierweiler.de)

---

<div class="post-metadata">

### Author: ![Joshua](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Joshua](https://community.letsencrypt.org/u/Joshua)
#### Post date: [October 26, 2020, 9:25am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/13 "2020-10-26T09:25:38Z")

</div>

Thank you so much guys!!

I'll try to remove the redirects aswell... thank you!!!!

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 9:26am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/14 "2020-10-26T09:26:42Z")

</div>

You're very welcome. 🙂 If your redirects end up as I've described, you will be in grand shape!

You might test your renewal just to be sure you'll end up with the right certificate. It should include both domain names ([www.gemeinde-trierweiler.de](http://www.gemeinde-trierweiler.de) and [gemeinde-trierweiler.de](http://gemeinde-trierweiler.de)).

`certbot renew --dry-run`

* * *

As @JuergenAuer mentioned earlier, you can use the following to view your certificates:  
`certbot certificates`

Note the _name_ of any certificate that does **not** include both [www.gemeinde-trierweiler.de](http://www.gemeinde-trierweiler.de) and [gemeinde-trierweiler.de](http://gemeinde-trierweiler.de).

You can use the following to delete any useless certificates to keep them from renewing:  
`certbot delete --cert-name` _name_

---

<div class="post-metadata">

### Author: ![Joshua](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Joshua](https://community.letsencrypt.org/u/Joshua)
#### Post date: [October 26, 2020, 9:42am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/15 "2020-10-26T09:42:34Z")

</div>

Alright. Thank you a lot guys, you saved me a load of my nerves. 😃

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 9:44am UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/16 "2020-10-26T09:44:46Z")

</div>

Happy to help! 🙂 If you have any other questions or run into any further trouble, you know where to find us. Be well and godspeed! 👋

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [October 26, 2020, 12:26pm UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/17 "2020-10-26T12:26:40Z")

</div>

> [@griffin](#):
>
> --keep-until-expiring

@griffin That's the default, right? Why do you specifically add it to the command line? Might be confusing to some.

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 3:54pm UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/18 "2020-10-26T15:54:57Z")

</div>

@Osiris

Because `--keep-until-expiring` is **not** the default for `certonly` or `run`. It should be though (and require `--force-renewal` to override). This is **the reason** why we get so many rate-limited visitors! Almost no one knows about `--force-renewal`, which is why `renew` is a safe command.

`--keep-until-expiring`, `--keep`, `--reinstall`

> If the requested certificate matches an existing certificate, always keep the existing one until it is due for renewal (for the '`run`' subcommand this means reinstall the existing certificate). ( **default: Ask** )

To make matters **worse** :

> If a certificate is requested with `run` or `certonly` specifying a certificate name that already exists, Certbot updates the existing certificate. Otherwise a new certificate is created and assigned the specified name.

[https://certbot.eff.org/docs/using.html#re-creating-and-updating-existing-certificates](https://certbot.eff.org/docs/using.html#re-creating-and-updating-existing-certificates)

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [October 26, 2020, 4:14pm UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/19 "2020-10-26T16:14:02Z")

</div>

> [@griffin](#):
>
> This is **the reason** why we get so many rate-limited visitors!

I think that's just partially true, as your quote already says (what I should have known): the user gets a question about what to do. So _strictly_ speaking it's the users "fault", probably due to too little knowledge about what to do.

> [@griffin](#):
>
> To make matters **worse** :

Eh, no, that's not worse: using `--cert-name` obviously overwrites the previous certificate _if_ a new certificate is issued. That's the point of that paragraph.

---

<div class="post-metadata">

### Author: ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)
#### Post date: [October 26, 2020, 4:15pm UTC](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830/20 "2020-10-26T16:15:40Z")

</div>

> [@griffin](#):
>
> If a certificate is requested with `run` or `certonly` specifying a certificate name that already exists, Certbot updates the existing certificate.

~~And does not ask anything in regards to not being near expiry.~~ If you naively specify to do so.

> [@griffin](#):
>
> Otherwise (if the specified certificate name does not exist) a new certificate is created and assigned the specified name.

Even if a certificate already exists with the specified domain names that is not near expiry. (Does this one still happen, @Osiris?)

[Next page](https://community.letsencrypt.org/t/problem-with-certbot-renew/136830.md?page=2)
