Back to articles
Technology Insight

Automating Wildcard SSL Certificate Renewal via DNS Challenge with Certbot and Cloudflare API on Linux VPS

May 29, 2026

Introduction to Automated Wildcard SSL Management

In the modern enterprise IT landscape, securing web infrastructure is no longer optional; it is a critical baseline. While standard SSL certificates protect individual fully qualified domain names (FQDNs), modern distributed architectures—comprising microservices, staging environments, and client-specific portals—demand a more flexible solution. Wildcard SSL certificates allow organizations to secure an infinite number of subdomains (e.g., *.domain.com) under a single cryptographic umbrella.

However, managing Wildcard SSL certificates comes with an operational hurdle. Unlike standard certificates that can be validated via simple HTTP challenges, Let's Encrypt mandates the DNS-01 challenge for Wildcard issuance. Manually updating DNS TXT records every 90 days is inefficient and error-prone, risking costly downtime. This guide provides a definitive, production-ready walkthrough for automating Wildcard SSL renewals on a Linux VPS using Certbot and the Cloudflare API.

The Core Challenge: Why DNS-01 and Automation Matter

To issue a Wildcard certificate, Let's Encrypt must verify that you exercise administrative control over the entire root zone, not just a specific web directory. The standard HTTP-01 challenge (placing a file on your web server) is insufficient because it cannot prove ownership of non-existent or distributed subdomains.

The DNS-01 challenge requires the deployment of a specific token into a _acme-challenge.yourdomain.com TXT record. When Let's Encrypt queries your DNS provider and finds the matching token, the certificate is issued.

By leveraging the Cloudflare API, Certbot can programmatically create this TXT record, validate the domain, and erase the temporary record within seconds. This entirely eliminates manual intervention, ensuring continuous 100% uptime for your secure services.

Prerequisites and Environment Setup

Before initiating the deployment, verify that your infrastructure satisfies the following baseline technical requirements:

  • Linux VPS: Running a modern enterprise distribution (Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, or Debian 12 recommended).
  • Administrative Access: Root access or full sudo privileges on the host machine.
  • Cloudflare Account: Your target domain's authoritative nameservers must point to Cloudflare, and you must have permission to alter DNS zones.

Step 1: Provisioning a Secure Cloudflare API Token

Security best practices dictate adhering to the Principle of Least Privilege. Do not use your global Cloudflare API key for automation. Instead, generate a scoped API token restricted solely to editing the DNS records of your specific zone.

  1. Log in to the Cloudflare Dashboard, navigate to the top-right user profile icon, and select My Profile > API Tokens.
  2. Click Create Token and choose the Edit zone DNS template.
  3. Configure the following precise permissions:
    • Permissions: Zone > DNS > Edit
    • Zone Resources: Include > Specific zone > select your target domain.
  4. Click Continue to Summary and then Create Token.
  5. Critical: Copy the generated token string immediately. It will not be displayed again for security reasons.

Step 2: Installing Certbot and the Cloudflare DNS Plugin

We will utilize snapd to install Certbot. This guarantees access to the latest software versions and secure cryptographic dependencies, bypassing outdated upstream package repositories.

Execute the following sequence of commands on your Linux VPS:

# Update the local package repository index
sudo apt update && sudo apt upgrade -y

# Ensure snapd is installed and up-to-date
sudo apt install snapd -y
sudo snap install core; sudo snap refresh core

# Remove any existing native Certbot packages to prevent binary conflicts
sudo apt remove certbot -y

# Install Certbot via Snap
sudo snap install --classic certbot

# Create a symbolic link to expose the certbot binary to your system PATH
sudo ln -s /snap/bin/certbot /usr/bin/certbot

# Install the specialized Cloudflare DNS plugin via Snap
sudo snap install certbot-dns-cloudflare

Verify the installation success and plugin visibility by executing: certbot plugins. Ensure that certbot-dns-cloudflare is explicitly listed in the output.

Step 3: Storing API Credentials Securely on Linux

Certbot requires access to your Cloudflare API token. Because this token holds write permissions for your domain's DNS, it must be protected against unauthorized read access by other system users.

Create a dedicated configuration directory and file:

sudo mkdir -p /etc/letsencrypt
sudo nano /etc/letsencrypt/cloudflare.ini

Populate the cloudflare.ini file with the following directive, replacing the placeholder with your actual Cloudflare token:

# Cloudflare API token used by Certbot
dns_cloudflare_api_token = YOUR_CLOUDFLARE_API_TOKEN_HERE

Save and exit the text editor. To mitigate local privilege escalation risks, restrict file permissions so that only the root user can read or modify this sensitive credential:

sudo chmod 600 /etc/letsencrypt/cloudflare.ini

Step 4: Requesting the Wildcard SSL Certificate

With the environment prepared, invoke Certbot to execute the DNS-01 challenge and request your certificate. We will request a single certificate that covers both the root domain (domain.com) and all immediate subdomains (*.domain.com).

sudo certbot certonly \
  --dns-cloudflare \
  --dns-cloudflare-credentials /etc/letsencrypt/cloudflare.ini \
  --dns-cloudflare-propagation-seconds 60 \
  -d domain.com \
  -d '*.domain.com' \
  --preferred-challenges dns-01 \
  --rsa-key-size 4096 \
  --agree-tos \
  -m [email protected]

Parameters Breakdown:

  • certonly: Directs Certbot to acquire the certificate without automatically altering system web server configurations.
  • --dns-cloudflare-propagation-seconds 60: Instructs Certbot to wait 60 seconds after creating the TXT record, ensuring global DNS propagation across Cloudflare edge nodes before Let's Encrypt validation starts.
  • --rsa-key-size 4096: Enforces robust enterprise-grade 4096-bit RSA encryption keys.
  • -m [email protected]: The administrative email address for receiving automated Let's Encrypt expiration warnings.

Upon successful execution, Certbot will save your production-grade certificates and private keys to the following directory: /etc/letsencrypt/live/[domain.com/](https://domain.com/).

Step 5: Verifying the Automated Renewal Architecture

Let's Encrypt certificates are valid for 90 days. Certbot natively schedules an internal cron job or systemd timer that triggers a check twice daily. If a certificate is within 30 days of expiration, it initiates an automated renewal.

To guarantee that your automation framework is functioning correctly without hitting Let's Encrypt rate limits, execute a full end-to-end dry run simulation:

sudo certbot renew --dry-run

If the output concludes with a message stating "Your dry run was successful," your system configuration is flawless and fully automated.

Step 6: Automating Web Server Reloads Via Hooks

Even though Certbot automatically renews the certificate files on disk, running web services like Nginx or Apache cache these files in system memory. They will continue serving the old, expiring certificate until the service configuration is reloaded.

To solve this elegantly without causing downtime, use Certbot’s deploy-hook system. Edit the automated renewal configuration file:

sudo nano /etc/letsencrypt/renewal/domain.com.conf

Locate the [renewalparams] block at the bottom of the file and append the appropriate directive based on your operational web stack:

For Nginx Infrastructures:

renew_hook = systemctl reload nginx

For Apache Infrastructures:

renew_hook = systemctl reload apache2

Save the file. Whenever a renewal event succeeds, Certbot will instantly issue a graceful configuration reload to your web server, hot-swapping the cryptographic certificates cleanly without dropping an active user connection.

Conclusion

Implementing automated Wildcard SSL management via Certbot and the Cloudflare API provides a robust, self-healing security foundation for your web infrastructure. By moving validation to the DNS layer, you eliminate port 80 dependencies, decouple security configurations from local application logic, and protect your entire subdomain ecosystem effortlessly. This implementation guarantees that your Linux VPS remains resilient, secure, and production-ready indefinitely.

Automating Wildcard SSL Certificate Renewal via DNS Challenge with Certbot and Cloudflare API on Linux VPS | DPTCloud