Skip to content
Follow
Ubuntu Linux

How to Revoke Let’s Encrypt Certificates on Ubuntu Linux

Richard
Written by
Richard
Nov 6, 2019 Updated Aug 15, 2026 2 min read
How to Change Default Apps in Ubuntu
How to Change Default Apps in Ubuntu

Revoking a Let’s Encrypt SSL/TLS certificate on Ubuntu Linux immediately stops that security certificate from working on your website so web browsers no longer trust it. You typically need to cancel a certificate when your secret private key gets stolen or a new web host takes over managing your site security.

For instance, moving your domain to Google Cloud Load Balancing means Google handles security certificates for you, so you must cancel your old Let’s Encrypt files. This cleanup step prevents browser warning errors and keeps your active website security up to date.

⚡ Quick Answer

Revoke a Let’s Encrypt certificate by running `certbot revoke –cert-path /etc/letsencrypt/live/your_domain/cert.pem –key-path /etc/letsencrypt/live/your_domain/key.pem`. Confirm package removal with `sudo apt purge letsencrypt certbot`. Finally, delete the configuration directory using `sudo rm -rf /etc/letsencrypt`.

Validate Certificate file

Before revoking a Let’s Encrypt certificate, you must first confirm you have the right certificate file. Revoking a certificate is a permanent action that cannot be undone. Once a certificate is revoked, browsers will show warnings because the certificate authority will no longer consider it trustworthy.

Revoking a certificate alerts the certificate authority via the Online Certificate Status Protocol (OCSP). Browsers query this system to verify whether they should still trust the site.

Revoke a Certificate for example.com

A Let’s Encrypt certificate for your domain, such as example.com, can be revoked using a specific command. This command prompts Certbot to begin revoking your certificate file. Remember to replace the example paths with the actual locations of your certificate and key files.

💻Code
certbot revoke --cert-path /etc/letsencrypt/live/example.com/cert.pem --key-path /etc/letsencrypt/live/example.com/key.pem

Let’s Encrypt typically stores its certificates and corresponding keys in the /etc/letsencrypt/live/example.com/ directory. Remember to replace example.com with the actual domain name for which you issued the certificate.

⚠️Warning
After running that command, you'll be asked to confirm that you want to remove the certificate's directory and folders. Type 'y' for yes.

Uninstall Let's Encrypt | Certbot

To completely stop using Let's Encrypt and Certbot on your Ubuntu system, uninstall them with a few commands. These commands will remove the software and all its related packages. You will need to type 'y' to confirm the removal when prompted.

🐧Bash / Shell
sudo apt update
sudo apt purge letsencrypt && sudo apt purge certbot

After running those commands, you'll be asked to confirm that you want to remove the listed packages. Type 'y' for yes.

Finally, run the commands below to remove Let's Encrypt directories.

🐧Bash / Shell
sudo rm -rf /etc/letsencrypt

The cleanup is now complete.

Conclusion:

You've now learned how to revoke Let's Encrypt certificates and uninstall associated packages and directories. If you encounter any issues with these steps, please leave a comment below.

You might also find the following post helpful:

Was this guide helpful?

Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.

📚 Related Tutorials

How to Install GNOME Desktop on Ubuntu 24.04
Ubuntu Linux How to Install GNOME Desktop on Ubuntu 24.04
How to Install KDE Desktop on Ubuntu 24.04
Ubuntu Linux How to Install KDE Desktop on Ubuntu 24.04
How to Get Free Wildcard SSL Certificates
Ubuntu Linux How to Get Free Wildcard SSL Certificates
How to Setup Let's Encrypt with Apache on Ubuntu Linux
Ubuntu Linux How to Setup Let's Encrypt with Apache on Ubuntu Linux

0 Comments

  • Hassan Javed

    key.pem isn’t there but privkey.pem is. What should I do?

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *