You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否继续使用未过期的Let's Encrypt证书?——系统升级与Certbot迁移期间的证书保留问询

Answers to Your Let's Encrypt & Certbot Questions

Hey there, let's tackle your questions clearly and directly:

1. Can I keep using an unexpired Let's Encrypt certificate even if a new version exists?

Absolutely! Let's Encrypt doesn't force you to switch to newly issued certificates as long as your existing one is still valid (within its 90-day lifespan) and you have the intact private key and certificate files. You can continue configuring HAProxy to use this old certificate right up until it expires—no rules or restrictions stop you from doing this.

2. Can I retain a copy of my current certificate and use it until it expires without revocation during system/Certbot upgrades?

You absolutely can, and this is actually a highly recommended practice to avoid downtime or unexpected issues. Here's what you need to know:

  • Backup your certificates first: Copy the entire /etc/letsencrypt directory (this includes both the live/ symlinks and the actual certificate files in archive/) to a secure location—like an external drive or a separate server. This backup is completely safe; simply copying these files will not trigger a revocation from Let's Encrypt. Revocation only happens if you explicitly run a command like certbot revoke, or if Let's Encrypt detects a compromise of your private key (which won't happen from a backup).
  • Your certificate won't get revoked during upgrades: As long as you don't run any revocation commands, your existing certificate will remain valid. When upgrading Ubuntu from 14.04 to 16.04, 18.04, then 20.04, keeping a backup of /etc/letsencrypt ensures you can restore your certificate setup if anything goes wrong during the upgrade process.
  • Safe upgrade workflow tips:
    • Before starting any system upgrades, take a full server backup (not just certificates) to cover all bases.
    • Once you're on Ubuntu 20.04 and install the new Snap-based Certbot, you can test it first with a single test domain to make sure it works with your HAProxy setup before touching your large set of existing domains.
    • Keep your old certificate files in place until the new ones are successfully issued and configured in HAProxy. You can even run both side-by-side if needed, but once the new certificate is working, you can keep the old one as a fallback until it expires.

If your HAProxy configuration points to the correct certificate file paths during the upgrade process, it will keep serving the old certificate without interruption. If you ever need to revert, just point HAProxy to your backed-up certificate files.


内容的提问来源于stack exchange,提问作者samueletc

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 03:59:09