crontool
Paste a schedule, read it in English, see the next runs.

Auto-Renew SSL Certificates with Cron (certbot)

Let's Encrypt recommends running certbot renew twice a day. certbot only renews certificates within 30 days of expiry, so running often is safe and ensures a renewal is never missed if one attempt fails.

The crontab line

0 0,12 * * * /usr/bin/certbot renew --quiet

This runs at midnight and noon. --quiet suppresses output unless there's an error. certbot skips certs that aren't near expiry, so the twice-daily run is a no-op most days.

Reload the web server after renewal

Use a deploy hook so nginx only reloads when a cert actually changed:

0 0,12 * * * /usr/bin/certbot renew --quiet --deploy-hook "systemctl reload nginx"

Check the systemd timer first

Modern certbot installs ship a systemd timer that already does this. Run systemctl list-timers | grep certbot; if it exists you don't need a cron job at all.

FAQ

What is the cron line to renew Let's Encrypt certificates?

0 0,12 * * * /usr/bin/certbot renew --quiet runs certbot twice a day. It only renews certs within 30 days of expiry, so it's a no-op most days.

Why run certbot renew twice a day instead of once?

Let's Encrypt officially recommends twice daily so that if one attempt fails (network blip, rate limit), the second still has a chance well before expiry.

How do I reload nginx after a cert renews?

Add --deploy-hook "systemctl reload nginx" so the reload only fires when a certificate actually changed, not on every no-op run.