From 18631b99ef9e03713e6450145f86461c05851877 Mon Sep 17 00:00:00 2001 From: ohemorange Date: Thu, 27 May 2021 23:27:56 -0700 Subject: [PATCH] Add instructions for setting up a cronjob in the docs (#8870) * Add instructions for setting up a cronjob in the docs * Be more specific about where the cron entry will be created Co-authored-by: alexzorin * Correct &s to &s Co-authored-by: alexzorin * Correct other & to & Co-authored-by: alexzorin * De-weasel the double-scheduled-task comment Co-authored-by: alexzorin * Have users create directory hooks instead of command line hooks * Use sudo in command Co-authored-by: alexzorin * tell windows users to ignore these instructions instead of telling them they won't work * Use the same commands that we have in the general instructions Co-authored-by: alexzorin --- certbot/docs/using.rst | 48 ++++++++++++++++++++++++++++++++++++++---- 1 file changed, 44 insertions(+), 4 deletions(-) diff --git a/certbot/docs/using.rst b/certbot/docs/using.rst index 29d0c9814..1c68c0ac1 100644 --- a/certbot/docs/using.rst +++ b/certbot/docs/using.rst @@ -695,10 +695,50 @@ is done by means of a scheduled task which runs ``certbot renew`` periodically. If you are unsure whether you need to configure automated renewal: -1. Review the instructions for your system at https://certbot.eff.org/instructions. - They will describe how to set up a scheduled task, if necessary. -2. (Linux/BSD): Check your system's crontab (typically `/etc/crontab` and - `/etc/cron.*/*`) and systemd timers (``systemctl list-timers``). +1. Review the instructions for your system and installation method at + https://certbot.eff.org/instructions. They will describe how to set up a scheduled task, + if necessary. If no step is listed, your system comes with automated renewal pre-installed, + and you should not need to take any additional actions. +2. On Linux and BSD, you can check to see if your installation method has pre-installed a timer + for you. To do so, look for the ``certbot renew`` command in either your system's crontab + (typically `/etc/crontab` or `/etc/cron.*/*`) or systemd timers (``systemctl list-timers``). +3. If you're still not sure, you can configure automated renewal manually by following the steps + in the next section. Certbot has been carefully engineered to handle the case where both manual + automated renewal and pre-installed automated renewal are set up. + +Setting up automated renewal +~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +If you think you may need to set up automated renewal, follow these instructions to set up a +scheduled task to automatically renew your certificates in the background. If you are unsure +whether your system has a pre-installed scheduled task for Certbot, it is safe to follow these +instructions to create one. + +If you're using Windows, these instructions are not neccessary as Certbot on Windows comes with +a scheduled task for automated renewal pre-installed. + +Run the following line, which will add a cron job to `/etc/crontab`: + +.. code-block:: shell + + SLEEPTIME=$(awk 'BEGIN{srand(); print int(rand()*(3600+1))}'); echo "0 0,12 * * * root sleep $SLEEPTIME && certbot renew -q" | sudo tee -a /etc/crontab > /dev/null + +If you needed to stop your webserver to run Certbot, you'll want to +add ``pre`` and ``post`` hooks to stop and start your webserver automatically. +For example, if your webserver is HAProxy, run the following commands to create the hook files +in the appropriate directory: + +.. code-block:: shell + + sudo sh -c 'printf "#!/bin/sh\nservice haproxy stop\n" > /etc/letsencrypt/renewal-hooks/pre/haproxy.sh' + sudo sh -c 'printf "#!/bin/sh\nservice haproxy start\n" > /etc/letsencrypt/renewal-hooks/post/haproxy.sh' + sudo chmod 755 /etc/letsencrypt/renewal-hooks/pre/haproxy.sh + sudo chmod 755 /etc/letsencrypt/renewal-hooks/post/haproxy.sh + +Congratulations, Certbot will now automatically renew your certificates in the background. + +If you are interested in learning more about how Certbot renews your certificates, see the +`Renewing certificates`_ section above. .. _where-certs: