Where Does Certbot Store Certificates?
Certbot keeps certs in /etc/letsencrypt with live symlinks, archive history, and renewal configs. Back up the whole tree.
Last updated
Certbot organizes certificates as lineages. Each domain set gets a folder in archive with every issuance, a live folder of symlinks to the newest, and a renewal config tying them together.
Partial copies break the chain. Live symlinks dangle without archive, renewals fail without their configs. Tar the whole /etc/letsencrypt tree and restore it whole.
Where Certbot stores this, by platform
/etc/letsencrypt
live, archive, renewal, accounts. Back up entire tree with symlinks intact. Renewal hooks live here too.
Frequently asked questions
How do I move Certbot certs to a new server?
Copy all of /etc/letsencrypt: live, archive, and renewal together. Symlinks between them must survive, so archive with tar, not plain copy.
Where is the renewal config for one domain?
Edit the file in /etc/letsencrypt/renewal for that lineage. Test with certbot renew --dry-run before relying on it.
live versus archive: which do servers use?
live holds symlinks to the current files in archive. Point web servers at live paths and renewals swap underneath without config edits.
Notice an outdated path? Let us know.