The Certbot 1,690 project recommends its snap; pip 21,050 is supported only "on a best effort basis" in a virtual environment. The snap is at 5.8.0 (1 September 2026), while Ubuntu 26.04 225 's apt package is 4.0.0, too old for IP address certificates, so remove any apt copy first. sudo snap install --classic certbot printed certbot 5.8.0 from Certbot Project (certbot-eff**) installed; then link it with sudo ln -s /snap/bin/certbot /usr/local/bin/certbot.
On a public server, sudo certbot --apache -d example.com -d www.example.com also configures the virtual host and the HTTPS redirect. For the test, Pebble 789 (https://github.com/letsencrypt/pebble 789 ) 2.10.1 listened on port 14000, its httpPort set to Apache 129 's port and pebble-challtestsrv resolving every name to 127.0.0.1. REQUESTS_CA_BUNDLE lets Certbot trust Pebble's endpoint, and certonly --webroot leaves Apache's configuration alone:
sudo REQUESTS_CA_BUNDLE=$HOME/pebble/pebble.minica.pem certbot certonly \
--server https://localhost:14000/dir --preferred-profile classic \
--webroot -w /var/www/example -d example.com -d www.example.com \
--agree-tos -m admin@example.com --no-eff-email
sudo certbot certificatesSuccessfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/example.com/fullchain.pem
Key is saved at: /etc/letsencrypt/live/example.com/privkey.pem
...
Certificate Name: example.com
Key Type: ECDSA
Identifiers: example.com www.example.com
Expiry Date: 2026-12-22 06:53:42+00:00 (VALID: 89 days)Pebble picks a random profile when none is named (the first attempt came back valid for six days), hence --preferred-profile classic. In the mod_ssl *:443 virtual host, point SSLCertificateFile and SSLCertificateKeyFile at fullchain.pem and privkey.pem in /etc/letsencrypt/live/example.com/, symlinks Certbot repoints on each renewal, never at the numbered files in archive/.