How to Delete Let’s Encrypt SSL Certificates
Deleting a Let’s Encrypt SSL certificate (a digital security file that secures a website) takes two stages. First you revoke the certificate, so the issuing authority knows to stop trusting it. Then you run Certbot, the official tool for managing these files, to remove them from your server. Certbot keeps its files in the /etc/letsencrypt/live folder. You will want to clean them out when a certificate expires, when the site is retired, or when the private key may have been exposed.
Revoking and deleting are separate jobs. Revoking tells the authority the certificate is no longer valid. Deleting only removes the local files and the renewal configuration. If the certificate was compromised, do both, and revoke first. Once the files are gone, a delete cannot be undone, though you can always request a new certificate for the same domain later.
Run sudo certbot delete –cert-name example.com in the terminal on your server, replacing example.com with your domain name. Certbot removes the certificate files, renewal configuration, and all associated data from /etc/letsencrypt/live. If unsure of the certificate name, run sudo certbot delete alone to see all certificates and select which to remove.
How to delete Let’s Encrypt SSL certificates on Ubuntu Linux
Connect to your server and type sudo certbot delete –cert-name example.com, replacing example.com with your actual domain name. This removes the certificate files and their configuration from the system, including the renewal settings, so Certbot will no longer try to renew that certificate.
You need an account with sudo rights. If you get a permission error, you are most likely running the command without sudo.
Here is the procedure, step by step. Before you start, make sure you have the exact certificate name. In most cases it is the primary domain name the certificate was issued for.
- Sign in to the server over SSH, or open a terminal directly on the machine.
- Run the command below, replacing example.com with the actual domain name.
sudo certbot delete --cert-name example.com
If you are not sure of the certificate name, run the command without referencing a domain name (leave out –cert-name and the domain). Certbot then lists all the certificates registered on the server and lets you pick one. This is also the safest route on a server that hosts several sites, because you can see exactly what is there before anything is removed.
sudo certbot delete
Look through the resulting list and find the domain whose certificate you want to delete. Each entry has a number beside it. Read the names carefully, since a similar-looking domain or a subdomain may have its own entry.
Saving debug log to /var/log/letsencrypt/letsencrypt.log Which certificate(s) would you like to delete? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: example.com 2: example1.net 3: example2.org - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate numbers separated by commas and/or spaces, or leave input blank to select all options shown (Enter 'c' to cancel): 1
Match the target domain to its assigned number, type that number, and press ENTER. Certbot then removes the certificate and tells you the files for that domain were deleted.
One last check: if Apache or Nginx is still configured to use the deleted certificate files, the web server may fail to reload or start. Update or remove those references in the site configuration before you restart the service.
Related post:
Conclusion:
- Deleting Let's Encrypt SSL certificates using Certbot is essential for maintaining a secure and organized server environment.
- After revoking a certificate, remnants of the certificate may still exist on the server, which can be eliminated by using Certbot to delete them.
- Following the step-by-step process described in this post ensures that unnecessary certificates are removed, optimizing the server's security and efficiency.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
No comments yet — be the first to share your thoughts!