

It does have access to the HTTP root directories. But, it still can’t open port 80/443 when apache already has that port open.
EDIT: I guess my certbot renew just needs to be reconfigured to use a --webroot, so it doesn’t try to listen on it’s own.







While I do have some control over my DNS and can create arbitrary TXT entries, I can’t to that in an automated way easily. I’m using Gandi.net to host my DNS rather than running my own DNS sever(s).
EDIT: Gandi is listed https://community.letsencrypt.org/t/dns-providers-who-easily-integrate-with-lets-encrypt-dns-validation/86438 so maybe I can automate a DNS-01 challenge without too much issue, I just have to switch away from
certbotto one of the other tools.