# For SSL certificates - alternative to copying certificates

**URL:** <https://discourse.nodered.org/t/for-ssl-certificates-alternative-to-copying-certificates/55551>\
**Category:** Share Your Projects\
**Created:** [22 December 2021 10:19 UTC](https://discourse.nodered.org/t/for-ssl-certificates-alternative-to-copying-certificates/55551 "2021-12-22T10:19:14Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [22 December 2021 14:31 UTC](https://discourse.nodered.org/t/for-ssl-certificates-alternative-to-copying-certificates/55551/3 "2021-12-22T14:31:51Z")

</div>

Hi Brian, just re-read the thread [Node-RED SSL using Letsencrypt & Certbot](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606) where I wrote some time ago about the ownership issue that I had problems with, and the reason why I used the script. but if creating symlinks to the certificates in the 'live' folder works, then great.  
PS remember that the 'certificates' in the 'live' folder are actually symlinks to the actual certificates which are stored in the 'archive' folder

> [@Node-RED SSL using Letsencrypt & Certbot](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606/36):
>
> Node-RED normally runs as a 'user', and Letsencrypt creates the certificates in etc/letsencrypt/live/ with root ownership, and therefore without changing the ownership of the certificates to pi, node\_RED would not be able to read them. So... rather than start altering files that sit within the Letsencrypt directory, I prefer to copy the certificates to the node-RED user directory and then use chown to make them readable (it's all done by the script). That then keeps the two services independe…

> [@borpin](#):
>
> The `deploy` script was largely to restart Node-Red which is now not required

Yes, I mentioned about node-RED no longer needing a restart in the same thread.

> [@Node-RED SSL using Letsencrypt & Certbot](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606/1):
>
> ```auto
> cp /etc/letsencrypt/live/$domain/*.pem "$node_dir"/
> chown $node_user "$node_dir"/*.pem
> node-red-restart # Restart node-RED
> 
> ```
> 
> **EDIT:** _Since node-RED v1.1, it is unnecessary to include the last line in the script (node-red-restart) because the certificates can be re-loaded as a node-RED core function, without restarting. [See this post](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606/45) for more details._

I'll edit the post and remove the reference to `node-red-restart` now that most people are using node-RED v1.1.0 or newer, but keep the script, and at least users will have the option to use it, use symlinks, or whatever.

---

_[View the full topic](https://discourse.nodered.org/t/for-ssl-certificates-alternative-to-copying-certificates/55551)._
