能否继续使用未过期的Let's Encrypt证书?——系统升级与Certbot迁移期间的证书保留问询
Hey there, let's tackle your questions clearly and directly:
1. Can I keep using an unexpired Let's Encrypt certificate even if a new version exists?
Absolutely! Let's Encrypt doesn't force you to switch to newly issued certificates as long as your existing one is still valid (within its 90-day lifespan) and you have the intact private key and certificate files. You can continue configuring HAProxy to use this old certificate right up until it expires—no rules or restrictions stop you from doing this.
2. Can I retain a copy of my current certificate and use it until it expires without revocation during system/Certbot upgrades?
You absolutely can, and this is actually a highly recommended practice to avoid downtime or unexpected issues. Here's what you need to know:
- Backup your certificates first: Copy the entire
/etc/letsencryptdirectory (this includes both thelive/symlinks and the actual certificate files inarchive/) to a secure location—like an external drive or a separate server. This backup is completely safe; simply copying these files will not trigger a revocation from Let's Encrypt. Revocation only happens if you explicitly run a command likecertbot revoke, or if Let's Encrypt detects a compromise of your private key (which won't happen from a backup). - Your certificate won't get revoked during upgrades: As long as you don't run any revocation commands, your existing certificate will remain valid. When upgrading Ubuntu from 14.04 to 16.04, 18.04, then 20.04, keeping a backup of
/etc/letsencryptensures you can restore your certificate setup if anything goes wrong during the upgrade process. - Safe upgrade workflow tips:
- Before starting any system upgrades, take a full server backup (not just certificates) to cover all bases.
- Once you're on Ubuntu 20.04 and install the new Snap-based Certbot, you can test it first with a single test domain to make sure it works with your HAProxy setup before touching your large set of existing domains.
- Keep your old certificate files in place until the new ones are successfully issued and configured in HAProxy. You can even run both side-by-side if needed, but once the new certificate is working, you can keep the old one as a fallback until it expires.
If your HAProxy configuration points to the correct certificate file paths during the upgrade process, it will keep serving the old certificate without interruption. If you ever need to revert, just point HAProxy to your backed-up certificate files.
内容的提问来源于stack exchange,提问作者samueletc

