Vorwort: die Initiative von let’s encrypt finde ich toll, …
… was die Umsetzung angeht: ich würde Leute für weniger fabrizierte Kacke in Stahlöfen verschwinden lassen.
IMPORTANT NOTES: - Congratulations! Your certificate and chain have been saved at /etc/letsencrypt/live/[…]/fullchain.pem. Your cert will expire on […]. To obtain a new or tweaked version of this certificate in the future, simply run letsencrypt-auto again. To non-interactively renew *all* of your certificates, run "letsencrypt-auto renew" - If you like Certbot, please consider supporting our work by: Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate Donating to EFF: https://eff.org/donate-le
Ja, genau:
root@mail:~# cd letsencrypt/
root@mail:~/letsencrypt# ./letsencrypt-auto renew
Upgrading certbot-auto 0.7.0 to 0.9.3...
Replacing certbot-auto...
Creating virtual environment...
Installing Python packages...
Installation succeeded.
Saving debug log to /var/log/letsencrypt/letsencrypt.log
-------------------------------------------------------------------------------
Processing /etc/letsencrypt/renewal/mail.meine.endgeile.doma.in.conf
-------------------------------------------------------------------------------
Cert is due for renewal, auto-renewing...
Could not choose appropriate plugin: The manual plugin is not working; there may be problems with your existing configuration.
The error was: PluginError('Running manual mode non-interactively is not supported',)
Attempting to renew cert from /etc/letsencrypt/renewal/mail.meine.endgeile.doma.in.conf produced an unexpected error: The manual plugin is not working; there may be problems with your existing configuration.
The error was: PluginError('Running manual mode non-interactively is not supported',). Skipping.
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/mail.meine.endgeile.doma.in/fullchain.pem (failure)
1 renew failure(s), 0 parse failure(s)
Ohne Worte.

Gibt doch reichlich Alternativen: https://letsencrypt.org/docs/client-options/