---
title: "Notes on Auto-Issuing Free Let's Encrypt SSL Certificates with Certbot on Windows"
description: "How to use Certbot on Windows to issue free Let's Encrypt wildcard SSL certificates, plus a PowerShell script that uses robocopy to automatically copy certificates to an FRP server."
canonical_url: "https://blog.markkulab.net/en/post/ssl-certbot"
author: "Mark Ku"
author_url: "https://blog.markkulab.net/en/author/mark-ku"
site: "Mark Ku's Tech Notes"
date_published: "2021-12-27 01:01:01 +0800"
category: "Infra"
tags: ["ssl", "certbot", "windows", "lets encrypt", "powershell", "dns"]
language: "en"
license: "CC BY 4.0"
license_url: "https://creativecommons.org/licenses/by/4.0/"
attribution: "when reusing or quoting, credit the author and link back to the original"
---

# Notes on Auto-Issuing Free Let's Encrypt SSL Certificates with Certbot on Windows

## Notes on Auto-Issuing Let's Encrypt SSL Certificates with Certbot on Windows

## The Problem
Let's Encrypt is a well-established, free SSL certificate service, but each certificate is only valid for three months. That means re-issuing manually every three months — which is tedious. With Certbot you can drive Let's Encrypt issuance via commands and scheduled tasks, fully automated.

## Issuing a Certificate
### Download and install Certbot
[[Certbot installer download]](https://github.com/certbot/certbot/releases/download/v1.22.0/certbot-beta-installer-win32.exe)

Open Command Prompt (or PowerShell) as Administrator.
Switch to the directory `C:\Program Files (x86)\Certbot\bin`, or add it to your system PATH.
Test Certbot:
```
certbot –-version
certbot -h
```
### Run from PowerShell with admin privileges

```
certbot certonly --manual -m a4756830@gmail.com -d *.letgo.com.tw 
certbot certonly --manual -m a4756830@gmail.com -d *.markkulab.net
```

### Copy the DNS TXT record provided by Certbot
![Certbot command line output showing DNS TXT record for SSL certificate](https://blog.markkulab.net/content/markku/posts/ssl-certbot/images/OdtU1ue.png)

### Go to your DNS host's admin panel, add a TXT record, and paste in the value Certbot just gave you
![Dialog for adding a DNS TXT record for Certbot challenge](https://blog.markkulab.net/content/markku/posts/ssl-certbot/images/ImAn2fs.png)

### Press Enter to continue, and the certificate will be generated under `C:\Certbot\live`
![Certbot output confirming certificate saved paths in PowerShell](https://blog.markkulab.net/content/markku/posts/ssl-certbot/images/0q7ll6A.png)

### From here you can copy the cert to wherever it's needed.

## Renewing a Certificate
### Renewal command — certificates can only be renewed within 30 days of expiry. A single command lets Certbot renew automatically, but it seems only Nginx and Apache support fully automated renewal.

```
certbot renew
```

P.S. If the cert was just issued, this command will usually report "Cert not yet due for renewal" since it doesn't need renewing yet.

### Test whether renewal works
```
certbot renew --dry-run
```

## Later I wrote a script to manually fetch the cert and copy it to my FRP server
```
certbot certonly --manual -m a4756830@gmail.com -d *.letgo.com.tw 
certbot certonly --manual -m a4756830@gmail.com -d *.markkulab.net
NET USE X: \\192.168.50.52\Container\data
robocopy C:\Certbot\live X:\frpc /E
NET USE X: /delete
```


## References
[Reference 1](http://tech.smallya.net/2021/11/28/certbot-lets-encrypt-ssl%E6%86%91%E8%AD%89-iis-%E5%A4%9A%E5%9F%9F%E5%90%8D/)
[Reference 2](https://blog.miniasp.com/post/2021/02/11/Create-SSL-TLS-certificates-from-LetsEncrypt-using-Certbot)

---

## About this article and its author

Originally published on [Mark Ku's Tech Notes](https://blog.markkulab.net/en/post/ssl-certbot)

License: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) — when reusing or quoting, credit the author and link back to the original

### About the author

**[Mark Ku](https://blog.markkulab.net/en/author/mark-ku)** — Software Solution Provider

- 10+ years senior software engineer, now an AI Builder
- Focused on large-platform architecture — North-American e-commerce, AI SaaS subscription billing
- Combining AI Agents and automation to build evolvable product foundations

### Free tools built by the author

All of these are free to use:

- [Free PDF Sign Tool](https://blog.markkulab.net/en/tools/pdf-sign): Online PDF sign tool — draw, type, or upload a signature, then drag, resize, and download. Everything runs in your browser; nothing is uploaded.
- [VS Code Refactory](https://blog.markkulab.net/en/tools/refactory): Refactory is a VS Code refactoring extension: 34 actions plus a 37-rule code-smell inspection layer with a Code Health dashboard, across 18 languages, backed by 534 tests. It learns your repo's conventions: where interfaces live, where DI is registered, whether 'use client' belongs. It ranks files by git churn × complexity so you know what to fix first, and hands any smell to the Claude Code already on your machine. Free to use, and your source never leaves your computer.
- [DB-Kit Database Manager](https://blog.markkulab.net/en/tools/db-kit): DB-Kit is a lightweight, cross-platform database manager built with Tauri + Rust + React. Manage MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, MongoDB, Redis, Kafka, Elasticsearch and RabbitMQ from one consistent interface: passwords encrypted in the OS keychain, SSH tunnels, full CRUD, a visual query builder, stacked multi-statement result sets, cross-connection data transfer and compare/sync, Excel / CSV import & export, visualized execution plans, ER diagrams, scheduled backups, SQL stress testing with p50–p99 latency percentiles, a 15-rule SQL review engine, Kafka message browsing with monitoring & alerts, a bilingual UI (Traditional Chinese / English), a built-in AI assistant (natural-language SQL, AI review and tuning advice) and the dbk CLI. Free and open source (MIT), with installers for Windows, macOS and Linux.
- [VS Code Super Mermaid](https://blog.markkulab.net/en/tools/super-mermaid): Super Mermaid is a VS Code extension for beautiful Mermaid diagrams out of the box: auto-colored live preview, mouse pan & zoom, high-res PNG / SVG export, 21 templates and multiple themes. Free and open source (MIT).
- [React Super Mermaid](https://blog.markkulab.net/en/tools/react-super-mermaid): react-super-mermaid is an open-source React component library: render beautiful Mermaid diagrams with a single <MermaidViewer>, with built-in colorful / sketch themes, pan & zoom, in-diagram search, and high-res SVG / PNG export. Lightweight, SSR-safe, fully typed. Free and open source (MIT).
- [Jira / Confluence Super Mermaid](https://blog.markkulab.net/en/tools/jira-super-mermaid): An Atlassian Forge app: write Mermaid syntax directly inside a Jira issue or a Confluence page and get flowcharts, sequence diagrams, state machines and Gantt charts. 11 diagram types, SVG / PNG export, light and dark themes, full CJK support. Runs on Atlassian: your diagrams live in your own site and the app calls no third-party service. Free, coming soon to the Atlassian Marketplace.
- [Mermaid Live Preview](https://blog.markkulab.net/en/tools/mermaid-preview): Write Mermaid in your browser, see it render instantly, and share the whole diagram as a single link. No sign-up, nothing uploaded to a server, and mermaid.live share links work as-is.
- [React Intl Phone Number](https://blog.markkulab.net/en/tools/react-intl-phone-number): react-intl-phone-number is an open-source React component: framework-agnostic and antd-free, with E.164 in/out, a searchable flag / country-code dropdown, configurable validation levels (strict / mobile-strict / loose), themeable CSS, and i18n — phone logic powered by google-libphonenumber. Lightweight and fully typed. Free and open source (MIT).
- [Uptime Kuma Cluster](https://blog.markkulab.net/en/tools/uptime-kuma-cluster): Turn single-node Uptime Kuma into a highly available cluster: OpenResty + Lua smart load balancing, shared MariaDB state, health checks and automatic failover, plus cluster-management REST APIs. One Docker Compose command to start. Free and open source (MIT).
- [Special Education](https://blog.markkulab.net/en/education): Learning materials crafted for special education students

### Daily podcasts

- [Mark's Tech Insights — Daily AI News](https://blog.markkulab.net/en/category/tech-news): Daily curated AI and tech trends. Catch the latest developments via audio summaries — covering AI applications, software architecture, DevOps, and engineering practice. — RSS: https://blog.markkulab.net/feed.xml
- [AI股市蝦聊](https://blog.markkulab.net/en/category/ai-stock-chat): Every trading day, an AI-analyzed take on the Taiwan stock market, delivered as a two-host conversation covering the session and the next-day outlook. — RSS: https://blog.markkulab.net/ai-stock-chat/feed.xml
- [開源好物週報](https://blog.markkulab.net/en/category/open-source-weekly): A weekly two-host pick of free open-source tools surfaced from real Hacker News, GitHub, and Reddit buzz — what pain they solve and the fastest way to get started. — RSS: https://blog.markkulab.net/open-source-weekly/feed.xml

### Newsletter

[Subscribe to the newsletter](https://blog.markkulab.net/en/subscribe) — Be the first to know about new posts. No spam, unsubscribe anytime.
