Skip to content

Repository files navigation

Let's Encrypt Certificate Renewal Tool

A graphical (tkinter) Python application that automates certbot DNS-challenge renewal for DuckDNS (or any) domains.


Features

Feature Details
Dry-Run Simulated renewal – safe to test without touching live certs
Live Renewal Full certbot certonly --manual --preferred-challenges dns workflow
DNS Challenge display Extracted TXT token shown in the UI and copied to clipboard
Browser launch Opens DuckDNS management page so you can paste the TXT record
Admin check Detects and optionally elevates to admin/root at startup
Settings Persistent config (~/.certbot_renewer_config.json) for certbot path & domain
Scrollable log Full colour-coded certbot output in the UI

Requirements

  • Python 3.10+
  • certbot installed on the system
  • tkinter (usually bundled with CPython; on Debian/Ubuntu: sudo apt install python3-tk)

Running directly

# Linux / macOS (run as root for certbot)
sudo python3 certbot_renewer.py

# Windows (run from an elevated PowerShell / CMD)
python certbot_renewer.py

Building a standalone executable

Linux / macOS

chmod +x build.sh
./build.sh
# Output: dist/certbot_renewer

Windows

build.bat
REM Output: dist\certbot_renewer.exe

The build scripts install PyInstaller automatically via pip.


Workflow

  1. Enter (or confirm) the domain name.
  2. Click Dry-Run or Live Renewal.
  3. certbot is launched and its output streams into the log pane.
  4. When certbot produces the _acme-challenge TXT value the app:
    • Displays it in the DNS Challenge field.
    • Copies it to the clipboard.
    • Opens your browser to the DuckDNS management page.
  5. Set the TXT record in DuckDNS, then click OK in the dialog.
  6. certbot verifies the record; the app reports OK (success) or KO (failure).

Configuration file

Stored at ~/.certbot_renewer_config.json:

{
  "certbot_path": "/usr/bin/certbot",
  "domain": "duck-bill.duckdns.org"
}

Edit via Settings in the app or directly in the file.


Notes

  • On Linux/macOS certbot requires sudo. Either launch the script as root or click Elevate Privileges (which re-launches with sudo).
  • On Windows certbot is typically installed via WSL or a Windows port; adjust the certbot path in Settings accordingly.
  • DNS propagation can take 30–120 seconds; wait before clicking OK in the "Set DNS TXT Record" dialog.

About

Let's Encrypt Certificate Renewal Tool

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages