# "Re-using" an existing certificate

**URL:** <https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220>\
**Category:** Help\
**Created:** [October 24, 2023, 4:37pm UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220 "2023-10-24T16:37:15Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![L4Y](https://avatars.discourse-cdn.com/v4/letter/l/bbe5ce/32.png) [@L4Y](https://community.letsencrypt.org/u/L4Y)\
**Post date:** [October 24, 2023, 4:37pm UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/1 "2023-10-24T16:37:15Z")

</div>

I'm running a server with Docker container and installed the certificate inside the container.  
Sometimes I have to upgrade the server which means deleting the current container and running a new one with the new version. I've linked the "/etc/letsencrypt" folder with the host folder and when starting the new server, when I enter "certbot certificates" it shows me the certificate that I've created on the previous server but now I want to use this certificate on a new one. How can I do it without deleting and generating a new SSL?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [October 24, 2023, 5:15pm UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/2 "2023-10-24T17:15:35Z")

</div>

What happens if you run `certbot install` inside the container?

I mean, is there certbot inside the container?

You can install the same certificate in however many containers you want, even at the same time.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 24, 2023, 5:23pm UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/3 "2023-10-24T17:23:54Z")

</div>

> [@L4Y](#):
>
> now I want to use this certificate on a new one. How can I do it without deleting and generating a new SSL?

Simply migrate the `/etc/letsencrypt/` directory over. While doing so, make sure you're keeping the symbolic links intact.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 24, 2023, 6:05pm UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/4 "2023-10-24T18:05:13Z")

</div>

That is an option...  
But they would have to remember to migrate it back **before** upgrading [replacing the docker container with the latest directory info].

If they just link to that directory, then they can forget to migrate and still be OK.

I think I would prefer just using the @9peppe method:

> [@9peppe](#):
>
> run `certbot install` inside the container

[once for each cert in use]

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 24, 2023, 6:49pm UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/5 "2023-10-24T18:49:40Z")

</div>

The `certbot install` command is only used with the `apache` and `nginx` plugins and often those webservers are running in different Docker containers so that won't work, as the installer plugins won't work.

I'm also not sure if that's what OP is asking.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [October 24, 2023, 6:59pm UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/6 "2023-10-24T18:59:26Z")

</div>

That's where my doubt comes from.

And yet, the old principle "one service per container" is "not always" adhered to. (Mostly when people use containers to distribute software)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 25, 2023, 12:15am UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/7 "2023-10-25T00:15:51Z")

</div>

> [@Osiris](#):
>
> often those webservers are running in different Docker containers

Difficult to say what is going on here...  
Is the glass half empty OR half full?  
OR maybe both!

Yes, we are agreed, `certbot install` will only work if `certbot` can reach the web server config files.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 25, 2023, 12:22am UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/8 "2023-10-25T00:22:08Z")

</div>

If you read between the lines:

> [@L4Y](#):
>
> I'm running a server with Docker container and installed the certificate inside the container.
> 
> Sometimes I have to upgrade the server which means deleting the current container and running a new one with the new version. I've linked the "/etc/letsencrypt" folder with the host folder and when starting the new server, when I enter "certbot certificates" it shows me the certificate that I've created on the previous server but now I want to use this certificate on a new one. How can I do it without deleting and generating a new SSL?

You can almost see that they do have `certbot` running within the same Docker container.  
OR do they?

---

<div class="post-metadata">

**Author:** ![L4Y](https://avatars.discourse-cdn.com/v4/letter/l/bbe5ce/32.png) [@L4Y](https://community.letsencrypt.org/u/L4Y)\
**Post date:** [October 25, 2023, 7:14am UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/9 "2023-10-25T07:14:27Z")

</div>

Yes, the certbot is inside the container and yes, `certbot install` works for me. I was looking for this command with `certbot --help` but didn't find it. Knowing that I can save the SSL and use on another container.  
Thank you!

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 25, 2023, 9:12am UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/10 "2023-10-25T09:12:55Z")

</div>

> [@L4Y](#):
>
> I was looking for this command with `certbot --help` but didn't find it.

You can find it ALL here:  
[User Guide — Certbot documentation (eff-certbot.readthedocs.io)](https://eff-certbot.readthedocs.io/en/latest/using.html)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 24, 2023, 9:13am UTC](https://community.letsencrypt.org/t/re-using-an-existing-certificate/207220/11 "2023-11-24T09:13:47Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
