Automated certificate renewal for nginx
The nginx package writes the renewed certificate and key where your ssl_certificate directives point, reloads nginx, and connects over TLS to confirm the new certificate is the one being served.
package nginx-target 2.0.0
writeCertificatewriteChainwhen configuredwritePrivateKeyreloadNginxwhen configuredverifyServedwhen configured
At a glance
- Package
nginx-target 2.0.0- Compatibility
nginx >=1.0 <2.0- Runs from
- A Linux agent on the server
- Mechanism
- Files on disk · Service reload or restart · TLS verification
- Authentication
- Local - no remote login
- Capabilities
- Import certificateImport private keyReload serviceVerify deployment
- Deployment steps
- writeCertificate → writeChain* → writePrivateKey → reloadNginx* → verifyServed*
- Rollback
- None
- Key usage
- No requirement
* conditional step
What it does
The agent on the server writes the certificate followed by its chain, an optional separate chain file, and the private key - owned by nginx's worker user so nginx can read it - then reloads the systemd unit.
If you set a verification host, the agent opens a TLS connection after the reload and checks that nginx serves the new certificate. A mismatch fails the deployment.
How it runs
- 01
writeCertificate
Certificate plus chain is written to the ssl_certificate path.
- 02
writeChain
A separate chain file is written, if configured (ssl_trusted_certificate).
- 03
writePrivateKey
The key is written with the configured owner.
- 04
reloadNginx
The nginx systemd unit is reloaded.
- 05
verifyServed
A TLS connection checks the served certificate, if a verification host is set.
What you configure
- Certificate path (default /etc/nginx/ssl/fullchain.pem)
- Private key path (default /etc/nginx/ssl/privkey.pem)
- Optional chain path
- Key owner (www-data on Debian/Ubuntu, nginx on RHEL)
- systemd unit to reload
- Optional verification host and port
Prerequisites
- A Linux agent on the nginx server
- nginx configured to read the certificate and key paths you set
Limitations
- The package writes files and reloads; it does not edit nginx configuration.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Linux and containers
Documentation
Frequently asked questions
nginx
Does it replace certbot?
For the hosts it manages, yes: issuance, renewal, file placement and reload are handled by the agent, with central visibility and alerts.
Can it verify the result?
Yes. Set a verification host and the agent checks over TLS that nginx serves the new certificate after the reload.
Automate nginx
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.