Certbot download certificates only

Install certbot

Get certificate

Append –dry-run to below commands to test.

certbot-auto certonly --webroot -w /path/to/webroot/ -d

Concatenate the newly renewed certificate and private key (lighttpd example):

cat /etc/letsencrypt/live/ /etc/letsencrypt/live/ > /etc/lighttpd/qa.pem

Reload webserver.

Expand certificate

For expanding the certificate to new subdomains just add the new domain to above command i.e.:

certbot-auto certonly --webroot -w /var/www/ --expand -d -d

Tested on

  • Debian 8 Jessie
  • Debian 9 Stretch

