CERTBOT(1) Certbot CERTBOT(1) (NAME) certbot - HTTPS Let's Encrypt (SYNOPSIS) Certbot Let's Encrypt ACME ( Automated Certificate Management Environment) HTTPS . . : o (CA) Let's Encrypt o o o . (OPTIONS) usage: certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ... Certbot HTTPS/TLS/SSL . . SUBCOMMAND : (obtain, install, and renew certificates): (default) run certonly renew enhance -d DOMAINS --apache Apache --standalone --nginx Nginx --webroot webroot --manual -n --test-cert (staging) --dry-run "renew" "certonly" (manage certificates): certificates Certbot revoke ( --cert-name --cert-path) delete ( --cert-name) reconfigure ( --cert-name) (manage your account): register ACME unregister ACME update_account ACME show_account --agree-tos (Subscriber Agreement) ACME -m EMAIL (options): -h, --help -c CONFIG_FILE, --config CONFIG_FILE (: etc/letsencrypt/cli.ini/ ~/.config/letsencrypt/cli.ini) -v, --verbose -vvv (: 0) --max-log-backups MAX_LOG_BACKUPS Certbot . 0 Certbot . (: 1000) -n, --non-interactive, --noninteractive . (: False) --force-interactive Certbot . renew . (: False) -d DOMAIN, --domains DOMAIN, --domain DOMAIN . -d . Subject Alternative Names . . -0001 . (: Ask) --ip-address IP_ADDRESSES IP . IP --ip-address . IP Subject Alternative Names . (: []) --eab-kid EAB_KID External Account Binding (: None) --eab-hmac-key EAB_HMAC_KEY HMAC External Account Binding (: None) --eab-hmac-alg EAB_HMAC_ALG HMAC External Account Binding (: HS256) --cert-name CERTNAME . Certbot . ( '/' '\' ). 'certbot certificates' . . (: ) --dry-run (staging) Let's Encrypt () . 'certonly' 'renew' . . --pre-hook --post-hook . --deploy-hook --run-deploy-hooks . --server . (: False) --debug-challenges CA . `-v` FQDN . (: False) --required-profile REQUIRED_PROFILE (profile) ACME. ACME ( ) . preferred_profile . . (: None) --preferred-profile PREFERRED_PROFILE ACME . ACME . ( CA ). CA . (: None) --preferred-chain PREFERRED_CHAIN . CA Subject Common Name . . (: None) --preferred-challenges PREF_CHALLS ( "dns" "http,dns"). . https://certbot.eff.org/docs/using.html#plugins . ACME "http-01" "http" Certbot . (: []) --issuance-timeout ISSUANCE_TIMEOUT ( ) Certbot . (: 90) --user-agent USER_AGENT (user agent) . CA . Let's Encrypt "" . (: CertbotACMEClient/5.7.0 (certbot; OS_NAME OS_VERSION) Authenticator/XXX Installer/YYY (SUBCOMMAND; flags: FLAGS) Py/major.minor.patchlevel). : --duplicate --force-renew --allow-subset-of-names -n . --user-agent-comment USER_AGENT_COMMENT . Certbot . --user-agent . (: Foo-Wrapper/1.0) (: None) (automation): --keep-until-expiring, --keep, --reinstall ( 'run' ). (: Ask) --expand . (: Ask) --version --force-renewal, --renew-by-default . ( --keep-until-expiring ). --expand . (: False) --renew-with-new-domains . (: False) --reuse-key . (: False) --no-reuse-key . Certbot . --reuse-key . (: False) --new-key --reuse-key . --new-key --reuse-key . (: False) --allow-subset-of-names . . --csr . (: False) --agree-tos ACME (: Ask) --duplicate ( ) (: False) -q, --quiet . cron. --non-interactive . (: False) (security): --rsa-key-size N RSA. (: 2048) --key-type {rsa,ecdsa} . ** . (: ecdsa) --elliptic-curve N SECG . RFC 8446 . (: secp256r1) --must-staple OCSP Must-Staple . OCSP Stapling ( >= 2.3.3). (: False) --redirect HTTP HTTPS vhost . (: redirect install run enhance ) --no-redirect HTTP HTTPS vhost . (: redirect install run enhance ) --hsts Strict-Transport-Security HTTP. SSL . SSL Stripping. (: False) --uir "Content-Security-Policy: upgrade-insecure-requests" HTTP. //:https //:http. (: False) --staple-ocsp OCSP Stapling. OCSP TLS . (: False) --strict-permissions tmp/ . (: False) --auto-hsts max-age HTTP Strict Transport Security (: False) (testing): . --run-deploy-hooks `--dry-run` `reconfigure` . renewal-hooks . --no-directory-hooks . () . `reconfigure` . (: False) --test-cert, --staging (staging) Let's Encrypt () --server https://acme-staging-v02.api.letsencrypt.org/directory (: False) --debug (tracebacks) (: False) --no-verify-ssl ACME. Certbot REQUESTS_CA_BUNDLE . (: False) --http-01-port HTTP01_PORT http-01. Certbot . ACME 80 . (: 80) --http-01-address HTTP01_ADDRESS http-01 . (: ) --https-port HTTPS_PORT HTTPS. Nginx LE . (: 443) --break-my-certs (/) (: False) (paths): --cert-path CERT_PATH ( certonly --csr) (: None) --key-path KEY_PATH ( ) (: None) --fullchain-path FULLCHAIN_PATH ( ). (: None) --chain-path CHAIN_PATH . (: None) --config-dir CONFIG_DIR . (: etc/letsencrypt/) --work-dir WORK_DIR . (: var/lib/letsencrypt/) --logs-dir LOGS_DIR . (: var/log/letsencrypt/) --server SERVER URI ACME. (: https://acme-v02.api.letsencrypt.org/directory) (manage): : certificates Certbot delete renew ( --cert-name) revoke --cert-path --cert-name reconfigure --cert-name run: certonly: --deploy-hook DEPLOY_HOOK . --disable-hook-validation PATH . RENEWED_LINEAGE$ live ( "/etc/letsencrypt/live/example.com") RENEWED_DOMAINS$ ( "example.com www.example.com") (: None) --csr CSR (CSR) DER PEM. --csr 'certonly' . (: None) renew: 'renew' . 'renew' . `--dry-run`. `--cert-name` . https://certbot.eff.org/docs/using.html#renewal . --pre-hook PRE_HOOK . --disable-hook-validation PATH . standalone . / . pre-hook . (: None) --post-hook POST_HOOK / . --disable-hook-validation PATH . --pre-hook . / . post-hook . (: None) --disable-hook-validation --pre-hook / --post-hook / --deploy-hook PATH$ . . (: False) --no-directory-hooks Certbot. (: False) --disable-renew-updates "certbot renew" . TLS . (: False) --no-autorenew . (: False) certificates: Certbot delete: revoke: --reason {unspecified,keycompromise,affiliationchanged,superseded,cessationofoperation} . (: unspecified) --delete-after-revoke . (: Ask) --no-delete-after-revoke . 'renew' . (: Ask) register: -m EMAIL, --email EMAIL . : u1@example.com,u2@example.com (: Ask). --eff-email EFF (: Ask) --no-eff-email EFF (: Ask) update_account: unregister: . --account ACCOUNT_ID (: None) install: rollback: --checkpoints N N . (: 1) plugins: "plugins" --init . (: False) --prepare . (: False) --authenticators . (: None) --installers . (: None) enhance: TLS . show_account: "show_account": reconfigure: "reconfigure" : plugins: (Plugin Selection): Certbot . 'certbot plugins' . . --help . --configurator CONFIGURATOR . --authenticator --installer . (: Ask) -a AUTHENTICATOR, --authenticator AUTHENTICATOR . (: None) -i INSTALLER, --installer INSTALLER ( ). (: None) --apache Apache (: False) --nginx Nginx (: False) --standalone "standalone". (: False) --manual (: False) --webroot webroot. (: False) --dns-cloudflare DNS TXT ( Cloudflare DNS). (: False) --dns-digitalocean DNS TXT ( DigitalOcean DNS). (: False) --dns-dnsimple DNS TXT ( DNSimple DNS). (: False) --dns-dnsmadeeasy DNS TXT ( DNS Made Easy DNS). (: False) --dns-gehirn DNS TXT ( Gehirn Infrastructure Service DNS). (: False) --dns-google DNS TXT ( Google Cloud DNS). (: False) --dns-linode DNS TXT ( Linode DNS). (: False) --dns-luadns DNS TXT ( LuaDNS DNS). (: False) --dns-nsone DNS TXT ( NS1 DNS). (: False) --dns-ovh DNS TXT ( OVH DNS). (: False) --dns-rfc2136 DNS TXT ( BIND DNS). (: False) --dns-route53 DNS TXT ( AWS Route53 DNS). (: False) --dns-sakuracloud DNS TXT ( Sakura Cloud DNS). (: False) apache: Apache ( Apache Certbot .) --apache-enmod APACHE_ENMOD 'a2enmod' Apache (: None) --apache-dismod APACHE_DISMOD 'a2dismod' Apache (: None) --apache-le-vhost-ext APACHE_LE_VHOST_EXT SSL vhost (: -le-ssl.conf) --apache-server-root APACHE_SERVER_ROOT Apache (: etc/apache2/) --apache-vhost-root APACHE_VHOST_ROOT VirtualHost Apache (: None) --apache-logs-root APACHE_LOGS_ROOT Apache (: var/log/apache2/) --apache-challenge-location APACHE_CHALLENGE_LOCATION (: etc/apache2/) --apache-handle-modules APACHE_HANDLE_MODULES ( Ubuntu/Debian) (: False) --apache-handle-sites APACHE_HANDLE_SITES ( Ubuntu/Debian) (: False) --apache-ctl APACHE_CTL Apache (: apache2ctl) --apache-bin APACHE_BIN apache2/httpd (: None) dns-cloudflare: DNS TXT ( Cloudflare DNS). --dns-cloudflare-propagation-seconds DNS_CLOUDFLARE_PROPAGATION_SECONDS DNS ACME DNS. (: 10) --dns-cloudflare-credentials DNS_CLOUDFLARE_CREDENTIALS INI Cloudflare. (: None) dns-digitalocean: DNS TXT ( DigitalOcean DNS). --dns-digitalocean-propagation-seconds DNS_DIGITALOCEAN_PROPAGATION_SECONDS DNS ACME DNS. (: 10) --dns-digitalocean-credentials DNS_DIGITALOCEAN_CREDENTIALS INI DigitalOcean. (: None) dns-dnsimple: DNS TXT ( DNSimple DNS). --dns-dnsimple-propagation-seconds DNS_DNSIMPLE_PROPAGATION_SECONDS DNS ACME DNS. (: 30) --dns-dnsimple-credentials DNS_DNSIMPLE_CREDENTIALS INI DNSimple. (: None) dns-dnsmadeeasy: DNS TXT ( DNS Made Easy DNS). --dns-dnsmadeeasy-propagation-seconds DNS_DNSMADEEASY_PROPAGATION_SECONDS DNS ACME DNS. (: 60) --dns-dnsmadeeasy-credentials DNS_DNSMADEEASY_CREDENTIALS INI DNS Made Easy. (: None) dns-gehirn: DNS TXT ( Gehirn Infrastructure Service DNS). --dns-gehirn-propagation-seconds DNS_GEHIRN_PROPAGATION_SECONDS DNS ACME DNS. (: 30) --dns-gehirn-credentials DNS_GEHIRN_CREDENTIALS Gehirn Infrastructure Service. (: None) dns-google: DNS TXT ( Google Cloud DNS DNS). --dns-google-propagation-seconds DNS_GOOGLE_PROPAGATION_SECONDS DNS ACME DNS. (: 60) --dns-google-credentials DNS_GOOGLE_CREDENTIALS JSON Google Cloud DNS Application Default Credentials (ADC). ( ADC https://cloud.google.com/docs/authentication/application-default-credentials https://developers.google.com/identity/protocols/OAuth2ServiceAccount#creatinganaccount Cloud DNS https://cloud.google.com/dns/access-control#permissions_and_roles .) (: None) --dns-google-project DNS_GOOGLE_PROJECT Google Cloud () Google Cloud DNS . . (: None) dns-linode: DNS TXT ( Linode DNS). --dns-linode-propagation-seconds DNS_LINODE_PROPAGATION_SECONDS DNS ACME DNS. (: 120) --dns-linode-credentials DNS_LINODE_CREDENTIALS INI Linode. (: None) dns-luadns: DNS TXT ( LuaDNS DNS). --dns-luadns-propagation-seconds DNS_LUADNS_PROPAGATION_SECONDS DNS ACME DNS. (: 30) --dns-luadns-credentials DNS_LUADNS_CREDENTIALS INI LuaDNS. (: None) dns-nsone: DNS TXT ( NS1 DNS). --dns-nsone-propagation-seconds DNS_NSONE_PROPAGATION_SECONDS DNS ACME DNS. (: 30) --dns-nsone-credentials DNS_NSONE_CREDENTIALS NS1. (: None) dns-ovh: DNS TXT ( OVH DNS). --dns-ovh-propagation-seconds DNS_OVH_PROPAGATION_SECONDS DNS ACME DNS. (: 120) --dns-ovh-credentials DNS_OVH_CREDENTIALS INI OVH. (: None) dns-rfc2136: DNS TXT ( BIND DNS). --dns-rfc2136-propagation-seconds DNS_RFC2136_PROPAGATION_SECONDS DNS ACME DNS. (: 60) --dns-rfc2136-credentials DNS_RFC2136_CREDENTIALS INI RFC 2136. (: None) dns-route53: DNS TXT ( AWS Route53 DNS). dns-sakuracloud: DNS TXT ( Sakura Cloud DNS). --dns-sakuracloud-propagation-seconds DNS_SAKURACLOUD_PROPAGATION_SECONDS DNS ACME DNS. (: 90) --dns-sakuracloud-credentials DNS_SAKURACLOUD_CREDENTIALS Sakura Cloud. (: None) manual: . . . CERTBOT_IDENTIFIER$ IP . HTTP-01 DNS-01 CERTBOT_VALIDATION$ CERTBOT_TOKEN$ HTTP-01 . CERTBOT_AUTH_OUTPUT$ stdout . HTTP-01 DNS-01 CERTBOT_REMAINING_CHALLENGES$ CERTBOT_ALL_IDENTIFIERS$ . --manual-auth-hook MANUAL_AUTH_HOOK (: None) --manual-cleanup-hook MANUAL_CLEANUP_HOOK (: None) nginx: Nginx --nginx-server-root NGINX_SERVER_ROOT Nginx. (: etc/nginx/ usr/local/etc/nginx/) --nginx-ctl NGINX_CTL 'nginx' 'configtest' Nginx. (: nginx) --nginx-sleep-seconds NGINX_SLEEP_SECONDS Nginx (reload). (: 1) null: (Null Installer) standalone: HTTP /.well-known/acme-challenge/ . . HTTP ( ). webroot: .well-known/acme-challenge/ webroot . HTTP webroot . HTTP ( ). --webroot-path WEBROOT_PATH, -w WEBROOT_PATH public_html / webroot. webroot . : `-w /var/www/example -d example.com -d www.example.com -w /var/www/thing -d thing.net -d m.thing.net` (: Ask) --webroot-map WEBROOT_MAP JSON webroot -d --ip-address . (escape) . : --webroot-map '{"eg1.is,m.eg1.is":"/www/eg1/", "eg2.is":"/www/eg2"}' w / -d- . webroot-map : webroot-map = {"example.com":"/var/www"}. (: {}) (AUTHOR) Certbot (COPYRIGHT) 2014-2018 - Certbot Apache 2.0 https://eff.org/cb-license . 5.7 July 7, 2026 CERTBOT(1)