mod_md (since 2.4.30, still labeled experimental) is an ACME client inside Apache 129 : name the domains, and it orders the certificate, answers the challenge and feeds mod_ssl, with no Certbot 1,690 and no timer.
MDContactEmail admin@example.com
MDCertificateAgreement accepted
MDProfile tlsserver
MDomain example.com www.example.com
<VirtualHost *:443>
ServerName example.com
# no certificate lines: mod_md supplies them
SSLEngine on
</VirtualHost>Port 443 or 80 must be reachable from the internet for the tls-alpn-01 or http-01 challenge; wildcards need dns-01 and an MDChallengeDns01 script. MDProfile (2.4.64 and later) picks a Let's Encrypt 1,144 profile: classic 90 days, tlsserver 45, shortlived 160 hours. Renewal starts with a third of the lifetime left, or when the CA asks through ARI (RFC 9773). The catch: mod_md does not reload Apache, and a renewed certificate waits until the next reload, so point MDMessageCmd at a script that runs systemctl reload apache2 on the renewed event. The file passes configtest; issuance needs a public DNS name and could not be run here. acme.sh and mod_md compares mod_md with Certbot and acme.sh 47,741 .