Automated certificates for Linux services
Most Linux services read their certificate from two PEM files and pick up a new one on reload. The Linux package covers all of them: Apache, Postfix, Dovecot, and anything else that works the same way.
package linux-file-target 2.0.0
writeCertificatewritePrivateKeyreloadServicewhen configured
At a glance
- Package
linux-file-target 2.0.0- Compatibility
Linux (systemd) >=1.0 <2.0- Runs from
- A Linux agent on the server
- Mechanism
- Files on disk · Service reload or restart
- Authentication
- Local - no remote login
- Capabilities
- Import certificateImport private keyReload service
- Deployment steps
- writeCertificate → writePrivateKey → reloadService*
- Rollback
- None
- Key usage
- No requirement
* conditional step
What it does
The agent on the server writes the certificate followed by its chain to one path and the private key to another, then reloads the systemd unit you name.
For nginx and HAProxy there are dedicated packages with service-specific defaults - nginx also verifies the served certificate. For services that need more than files and a reload, use a custom shell script.
How it runs
- 01
writeCertificate
Certificate plus chain is written to the certificate path.
- 02
writePrivateKey
The key is written to the key path.
- 03
reloadService
The systemd unit is reloaded, if one is set.
What you configure
- Certificate path
- Private key path
- systemd unit to reload, for example apache2, postfix or dovecot
Prerequisites
- A Linux agent on the server
- A systemd-managed service that reads PEM files
Limitations
- No built-in verification step; use the nginx package or a custom script when you need one.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Linux and containers
Documentation
Frequently asked questions
Linux servers (Apache, Postfix, Dovecot)
Does it work for Postfix and Dovecot?
Yes. Point the paths at the files smtpd_tls_cert_file / ssl_cert reference and reload the service.
What about services that need a combined PEM?
HAProxy has its own package that writes a combined bundle. Anything else can use a custom script.
Automate Linux servers (Apache, Postfix, Dovecot)
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.