Auto-Renew SSL Certificates with Cron (certbot)
Let's Encrypt recommends running certbot renew twice a day. certbot only renews certificates within 30 days of expiry, so running often is safe and ensures a renewal is never missed if one attempt fails.
The crontab line
0 0,12 * * * /usr/bin/certbot renew --quiet
This runs at midnight and noon. --quiet suppresses output unless there's an error. certbot skips certs that aren't near expiry, so the twice-daily run is a no-op most days.
Reload the web server after renewal
Use a deploy hook so nginx only reloads when a cert actually changed:
0 0,12 * * * /usr/bin/certbot renew --quiet --deploy-hook "systemctl reload nginx"
Check the systemd timer first
Modern certbot installs ship a systemd timer that already does this. Run systemctl list-timers | grep certbot; if it exists you don't need a cron job at all.
FAQ
What is the cron line to renew Let's Encrypt certificates?
0 0,12 * * * /usr/bin/certbot renew --quiet runs certbot twice a day. It only renews certs within 30 days of expiry, so it's a no-op most days.
Why run certbot renew twice a day instead of once?
Let's Encrypt officially recommends twice daily so that if one attempt fails (network blip, rate limit), the second still has a chance well before expiry.
How do I reload nginx after a cert renews?
Add --deploy-hook "systemctl reload nginx" so the reload only fires when a certificate actually changed, not on every no-op run.