Where Are Let's Encrypt Certificates Stored?
Let's Encrypt live certificates, archive and renewal configs under /etc/letsencrypt on Linux.
Last updated
Certbot organizes /etc/letsencrypt into three parts: live holds symlinks servers point at, archive holds versioned cert generations, renewal holds per-cert issuance configs.
The symlink design means renewals never change the paths your server uses. New generations appear in archive; live flips to them.
Where Let's Encrypt stores this, by platform
/etc/letsencrypt/live
One subfolder per certificate with symlinks (fullchain.pem, privkey.pem) into archive. Root-only readable. Point web servers here, never into archive directly.
Frequently asked questions
Should I copy files out of the live folder?
Never edit or hand-copy inside live. It holds symlinks into archive managed by Certbot. Point servers at the live paths and let renewal update them in place.
What are the renewal config files for?
Renewal configs in the renewal folder record how each cert was issued. certbot renew reads them; deleting one silently drops that cert from future renewals.
Notice an outdated path? Let us know.