# Use set ssl cert with cert directory

**URL:** <https://discourse.haproxy.org/t/use-set-ssl-cert-with-cert-directory/5193>\
**Category:** Configuration Samples\
**Created:** [May 6, 2020, 2:17pm UTC](https://discourse.haproxy.org/t/use-set-ssl-cert-with-cert-directory/5193 "2020-05-06T14:17:45Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![bbot](https://avatars.discourse-cdn.com/v4/letter/b/b19c9b/32.png) [@bbot](https://discourse.haproxy.org/u/bbot)\
**Post date:** [March 9, 2022, 5:25pm UTC](https://discourse.haproxy.org/t/use-set-ssl-cert-with-cert-directory/5193/2 "2022-03-09T17:25:58Z")

</div>

Thanks @dbu. I’ve been using this strategy with certbot for a while now, but it stopped working recently. The issue, it turns out, is twofold.

1. The “chain.pem” file–which is included for convenience in “fullchain.pem”–issued by Let’s Encrypt now has an empty line. That blank line will need to be stripped out; otherwise, HAProxy will try to interpret part of the payload as a command and spit out “Unknown command…” errors.

2. `DOMAINS=$(ls ${LE_DIR})` doesn’t quite work anymore since `/etc/letsencrypt/live/` has a `README` file in it.

Lastly, I’d be hesitant to use `tee` since that may cause the private key to show up in logs. It may be more secure to use simple redirection (`>`).

I use the following, where “$CERT\_NAME” holds the name of the certificate (e.g. `$DOMAIN` in the original script), as issued to `certbot`'s `--cert-name` option.

```auto
LE_LIVE_DIR="/etc/letsencrypt/live/${CERT_NAME}"
LE_FULL_CERT_DIR=/etc/letsencrypt/full
FULL_CERT="${LE_FULL_CERT_DIR}/${CERT_NAME}.pem"

mkdir -p "${LE_FULL_CERT_DIR}"

# Create a single-file certificate with both the full CA chain and the
# private key. Empty lines are removed.
cat ${LE_LIVE_DIR}/fullchain.pem ${LE_LIVE_DIR}/privkey.pem | sed '/^$/d' > ${FULL_CERT}

```

Note the `sed` part, which removes the empty lines from `fullchain.pem`. Also note that I place the concatenated certificate in a new directory. Permissions and ownership should be set on the directory and file (e.g. owned by root with 600 permissions on the file).

---

_[View the full topic](https://discourse.haproxy.org/t/use-set-ssl-cert-with-cert-directory/5193)._
