# 1.2.3 Let's encrypt https ui without Nginx or Apache2

**URL:** <https://forum.genieacs.com/t/1-2-3-lets-encrypt-https-ui-without-nginx-or-apache2/1379>\
**Category:** Uncategorized\
**Created:** [January 22, 2021, 5:45am UTC](https://forum.genieacs.com/t/1-2-3-lets-encrypt-https-ui-without-nginx-or-apache2/1379 "2021-01-22T05:45:18Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![webtron](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/webtron/32/396_2.png) [@webtron](https://forum.genieacs.com/u/webtron)\
**Post date:** [January 22, 2021, 5:45am UTC](https://forum.genieacs.com/t/1-2-3-lets-encrypt-https-ui-without-nginx-or-apache2/1379/1 "2021-01-22T05:45:18Z")

</div>

I couldn’t find any laid out instructions for this and it’s missing from the install instructions so I thought I’d share.  
This is without using Nginx or Apache2 so it was harder to find info on setting it up and I want the certs to renew automatically.  
If you have nothing else running on port 80 you can run certbot in “standalone” mode. In standalone mode certbot will listen itself on port 80 for the authourization.  
Make sure you have your domain name pointing at your servers IP

> sudo apt update  
> sudo apt install certbot

Change [MyDomainExample.com](http://MyDomainExample.com) everywhere below to your domain name

> sudo certbot certonly --standalone --preferred-challenges http -d [MyDomainExample.com](http://MyDomainExample.com)

Enter your email address when prompted and answer the questions.

Edit the /opt/genieacs/genieacs.env and add these 2 lines

> GENIEACS\_UI\_SSL\_CERT=/etc/letsencrypt/live/MyDomainExample.com/fullchain.pem  
> GENIEACS\_UI\_SSL\_KEY=/etc/letsencrypt/live/MyDomainExample.com/privkey.pem

These permissions need to be changed to allow Genieacs to access the certificate and key. Hopefully these stay set on renewal or I’ll have to script it to reset them each renewal.

> sudo chmod 710 /etc/letsencrypt/live/  
> sudo chmod 710 /etc/letsencrypt/archive/  
> sudo chgrp genieacs /etc/letsencrypt/live  
> sudo chgrp genieacs /etc/letsencrypt/archive  
> sudo chown genieacs /etc/letsencrypt/live/MyDomainExample.com/privkey.pem  
> sudo chown genieacs /etc/letsencrypt/live/MyDomainExample.com/fullchain.pem

Get the renewal to auto restart the genieacs.ui you need to edit the /etc/letsencrypt/renewal/MyDomainExample.com.conf and add this as the last line

> renew\_hook = systemctl restart genieacs-ui

Test the renewal

> sudo certbot renew --dry-run

Test gui with

> [https://MyDomainExample.com:3000](https://MyDomainExample.com:3000)

---

_[View the full topic](https://forum.genieacs.com/t/1-2-3-lets-encrypt-https-ui-without-nginx-or-apache2/1379)._
