aethercert
Linux and containers

Automated certificate renewal for nginx

The nginx package writes the renewed certificate and key where your ssl_certificate directives point, reloads nginx, and connects over TLS to confirm the new certificate is the one being served.

The deployment steps defined in this package's manifest.

At a glance

Package
nginx-target 2.0.0
Compatibility
nginx >=1.0 <2.0
Runs from
A Linux agent on the server
Mechanism
Files on disk · Service reload or restart · TLS verification
Authentication
Local - no remote login
Capabilities
Import certificateImport private keyReload serviceVerify deployment
Deployment steps
writeCertificate → writeChain* → writePrivateKey → reloadNginx* → verifyServed*
Rollback
None
Key usage
No requirement

* conditional step

What it does

The agent on the server writes the certificate followed by its chain, an optional separate chain file, and the private key - owned by nginx's worker user so nginx can read it - then reloads the systemd unit.

If you set a verification host, the agent opens a TLS connection after the reload and checks that nginx serves the new certificate. A mismatch fails the deployment.

How it runs

  1. 01

    writeCertificate

    Certificate plus chain is written to the ssl_certificate path.

  2. 02

    writeChain

    A separate chain file is written, if configured (ssl_trusted_certificate).

  3. 03

    writePrivateKey

    The key is written with the configured owner.

  4. 04

    reloadNginx

    The nginx systemd unit is reloaded.

  5. 05

    verifyServed

    A TLS connection checks the served certificate, if a verification host is set.

What you configure

  • Certificate path (default /etc/nginx/ssl/fullchain.pem)
  • Private key path (default /etc/nginx/ssl/privkey.pem)
  • Optional chain path
  • Key owner (www-data on Debian/Ubuntu, nginx on RHEL)
  • systemd unit to reload
  • Optional verification host and port

Prerequisites

  • A Linux agent on the nginx server
  • nginx configured to read the certificate and key paths you set

Limitations

  • The package writes files and reloads; it does not edit nginx configuration.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

nginx

Does it replace certbot?

For the hosts it manages, yes: issuance, renewal, file placement and reload are handled by the agent, with central visibility and alerts.

Can it verify the result?

Yes. Set a verification host and the agent checks over TLS that nginx serves the new certificate after the reload.

Automate nginx

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.