Back to articles
Technology Insight

Automating Wildcard SSL Certificate Renewal with Certbot, DNS Challenge, and Cloudflare API on Linux VPS

May 29, 2026

Introduction to Automated Wildcard SSL Management

In the modern digital landscape, securing web applications is no longer optional; it is a foundational requirement. For enterprises and developers managing complex infrastructures with multiple subdomains, standard Single-Domain SSL certificates quickly become administrative burdens. This is where Wildcard SSL certificates become indispensable, allowing organizations to secure a root domain and an infinite number of first-level subdomains (e.g., *.domain.com) under a single cryptographic umbrella.

However, Let's Encrypt Wildcard certificates come with a strict 90-day validity period. Manual renewal is highly inefficient and prone to human error, which can result in costly downtime and broken trust. To address this, combining Certbot, the DNS-01 challenge protocol, and the Cloudflare API provides a robust, fully automated solution. This guide delivers an enterprise-grade walkthrough to setting up this automated pipeline on a Linux Virtual Private Server (VPS).

The Core Challenge: Why HTTP-01 Fails for Wildcard Certificates

Standard SSL automated renewals typically rely on the HTTP-01 challenge, where the Certificate Authority (CA) validates domain ownership by looking for a specific file served over HTTP. While highly effective for individual domains, the HTTP-01 challenge cannot be used to issue or renew Wildcard certificates.

Security Standard: The Automated Certificate Management Environment (ACME) protocol explicitly mandates the use of the DNS-01 challenge for Wildcard certificate validation.

The DNS-01 challenge requires creating a specific TXT record under _acme-challenge.yourdomain.com. The CA queries the global DNS infrastructure to verify this record's existence, proving your administrative control over the entire DNS zone. To automate this without exposing vulnerable root credentials, we leverage Cloudflare's scoped API tokens, allowing Certbot to dynamically create, verify, and purge these DNS records programmatically.

Prerequisites and Environmental Setup

Before initiating the configuration, ensure your environment meets the following baseline technical criteria:

  • Operating System: A modern Linux distribution (Ubuntu 20.04/22.04 LTS or Debian 11/12 preferred) with root or sudo administrative privileges.
  • DNS Infrastructure: The target domain's nameservers must be fully delegated to and managed by Cloudflare.
  • Network Accessibility: Outbound HTTPS access (port 443) enabled via your VPS firewall to communicate with Let's Encrypt and Cloudflare endpoints.

Step 1: Securing a Scoped Cloudflare API Token

To follow the principle of least privilege, do not use your global Cloudflare API key. Instead, create a highly restricted API token tailored exclusively for DNS record modification.

  • Log in to your Cloudflare Dashboard and navigate to My Profile > API Tokens.
  • Click Create Token and choose the Edit zone DNS template.
  • Configure the token permissions precisely as follows:
    • Permissions: Zone | DNS | Edit
    • Zone Resources: Include | Specific zone | Select your target domain
  • Set an optional expiration date if required by your corporate compliance policy, then click Continue to Summary and Create Token.
  • Note: Copy the generated token string immediately. For security reasons, Cloudflare will not display this value again.

    Step 2: Installing Certbot and the Cloudflare DNS Plugin

    Using standard package managers like apt can sometimes result in outdated software versions. To ensure complete compatibility and stability, use Snapd to install Certbot and its official Cloudflare plugin.

    Execute the following commands sequentially on your Linux VPS terminal:

    # Update the system package repository
    sudo apt update && sudo apt upgrade -y
    
    # Ensure Snapd is installed and up to date
    sudo apt install snapd -y
    sudo snap install core; sudo snap refresh core
    
    # Remove existing native Certbot installations to prevent conflicts
    sudo apt remove certbot -y
    
    # Install Certbot via Snap
    sudo snap install --classic certbot
    
    # Create a symlink to ensure the certbot command is globally accessible
    sudo ln -s /snap/bin/certbot /usr/bin/certbot
    
    # Install the official Certbot Cloudflare DNS plugin
    sudo snap install certbot-dns-cloudflare

    Verify the successful integration of the plugin by listing all installed Certbot components: certbot plugins. You should see dns-cloudflare listed clearly in the output configuration.

    Step 3: Configuring the Secure Cloudflare Credentials File

    Certbot requires access to your API token to execute automated operations. Because this file contains sensitive access credentials, it must be fiercely protected against unauthorized local read access.

    Create a dedicated configuration directory and file:

    sudo mkdir -p /etc/letsencrypt
    sudo nano /etc/letsencrypt/cloudflare.ini

    Populate the file with the following directive, replacing the placeholder with your actual Cloudflare API token:

    # Cloudflare API token used by Certbot for DNS-01 challenges
    dns_cloudflare_api_token = your_secret_cloudflare_api_token_here

    Save and exit the editor. Next, enforce strict POSIX permissions to restrict access exclusively to the root user:

    sudo chmod 600 /etc/letsencrypt/cloudflare.ini

    This step is critical. Leaving this file world-readable poses a severe security risk, allowing any compromised local application to manipulate your public DNS zones.

    Step 4: Requesting the Wildcard SSL Certificate

    With the infrastructure prepared, execute the Certbot command to initialize the DNS-01 challenge and obtain your Wildcard SSL certificate. This single certificate will cover both your root domain and all nested subdomains.

    sudo certbot certonly \
      --dns-cloudflare \
      --dns-cloudflare-credentials /etc/letsencrypt/cloudflare.ini \
      --dns-cloudflare-propagation-seconds 60 \
      -d yourdomain.com \
      -d *.yourdomain.com \
      --agree-tos \
      --no-eff-email \
      -m [email protected]

    Deconstructing the Command Parameters:

    • certonly: Instructs Certbot to fetch and store the cryptographic certificates without modifying local webserver configurations automatically.
    • --dns-cloudflare: Specifies the use of the Cloudflare DNS plugin for validation.
    • --dns-cloudflare-propagation-seconds 60: Delays validation for 60 seconds to guarantee that Cloudflare’s global edge network completely synchronizes the new TXT record before Let's Encrypt queries it.
    • -d yourdomain.com -d *.yourdomain.com: Defines the domains to include. Explicitly listing both ensures the root domain and all subdomains are covered by a single certificate.

    Upon successful execution, Certbot will save your keys and certificate chain within /etc/letsencrypt/live/[yourdomain.com/](https://yourdomain.com/).

    Step 5: Testing and Validating Automated Renewals

    The core objective of this architecture is hands-free maintenance. Snapd automatically installs a systemd timer or cron job to check for certificate expirations twice daily. However, you must perform a dry-run execution to verify that the automated renewal script functions seamlessly without manual intervention.

    sudo certbot renew --dry-run

    Review the terminal output carefully. If the process completes with a success message indicating that the simulated renewal was successful, your automation architecture is fully operational and production-ready.

    Step 6: Deploying Post-Hook Automation Scripts

    Obtaining and renewing certificates automatically is only half the battle. When a certificate is successfully renewed, target services such as Nginx, Apache, or HAProxy must be reloaded to read the updated cryptographic keys from disk without dropping active client connections.

    To automate this seamlessly, configure a Certbot deploy hook. Open or create the global renewal configuration file for your domain:

    sudo nano /etc/letsencrypt/renewal/yourdomain.com.conf

    Navigate to the [renewalparams] section and append the following line, customizing it to match your specific web server ecosystem:

    renew_hook = systemctl reload nginx

    This directive guarantees that the moment a real certificate renewal occurs, your webserver safely hot-reloads its configuration, mitigating any risks of serving expired credentials to your visitors.

    Conclusion and Best Practices

    Automating Wildcard SSL certificates via the Certbot Cloudflare DNS-01 plugin is a definitive strategy for modern infrastructure administration. By abstracting away the operational overhead of certificate management, you eliminate human error and secure your entire web ecosystem proactively. To ensure long-term operational stability, periodically monitor your Linux system logs via journalctl -u certbot.timer and audit your Cloudflare API token usage logs to maintain a clean, resilient, and enterprise-secure platform.

    Automating Wildcard SSL Certificate Renewal with Certbot, DNS Challenge, and Cloudflare API on Linux VPS | DPTCloud