A graphical (tkinter) Python application that automates certbot DNS-challenge
renewal for DuckDNS (or any) domains.
| Feature | Details |
|---|---|
| Dry-Run | Simulated renewal – safe to test without touching live certs |
| Live Renewal | Full certbot certonly --manual --preferred-challenges dns workflow |
| DNS Challenge display | Extracted TXT token shown in the UI and copied to clipboard |
| Browser launch | Opens DuckDNS management page so you can paste the TXT record |
| Admin check | Detects and optionally elevates to admin/root at startup |
| Settings | Persistent config (~/.certbot_renewer_config.json) for certbot path & domain |
| Scrollable log | Full colour-coded certbot output in the UI |
- Python 3.10+
certbotinstalled on the systemtkinter(usually bundled with CPython; on Debian/Ubuntu:sudo apt install python3-tk)
# Linux / macOS (run as root for certbot)
sudo python3 certbot_renewer.py
# Windows (run from an elevated PowerShell / CMD)
python certbot_renewer.pychmod +x build.sh
./build.sh
# Output: dist/certbot_renewerbuild.bat
REM Output: dist\certbot_renewer.exeThe build scripts install PyInstaller automatically via pip.
- Enter (or confirm) the domain name.
- Click Dry-Run or Live Renewal.
- certbot is launched and its output streams into the log pane.
- When certbot produces the
_acme-challengeTXT value the app:- Displays it in the DNS Challenge field.
- Copies it to the clipboard.
- Opens your browser to the DuckDNS management page.
- Set the TXT record in DuckDNS, then click OK in the dialog.
- certbot verifies the record; the app reports OK (success) or KO (failure).
Stored at ~/.certbot_renewer_config.json:
{
"certbot_path": "/usr/bin/certbot",
"domain": "duck-bill.duckdns.org"
}Edit via Settings in the app or directly in the file.
- On Linux/macOS certbot requires
sudo. Either launch the script as root or click Elevate Privileges (which re-launches withsudo). - On Windows certbot is typically installed via WSL or a Windows port; adjust the certbot path in Settings accordingly.
- DNS propagation can take 30–120 seconds; wait before clicking OK in the "Set DNS TXT Record" dialog.