# Renewing LetsEncrypt SSL certificates. Cannot decrypt the private key file

**URL:** <https://the.fmsoup.org/t/renewing-letsencrypt-ssl-certificates-cannot-decrypt-the-private-key-file/3598>\
**Category:** Questions\
**Tags:** filemaker-server, command-line\
**Created:** [June 7, 2023, 10:08am UTC](https://the.fmsoup.org/t/renewing-letsencrypt-ssl-certificates-cannot-decrypt-the-private-key-file/3598 "2023-06-07T10:08:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [June 7, 2023, 10:08am UTC](https://the.fmsoup.org/t/renewing-letsencrypt-ssl-certificates-cannot-decrypt-the-private-key-file/3598/1 "2023-06-07T10:08:06Z")

</div>

**Server Version** 19.5.4.400

I've been using LetsEncrypt to provide SSL certificates. Today as I ran the renewal process I got the error "Cannot decrypt the private key file XXXXX with the password. Please make sure the key file and password are correct.  
Error: 20408 (File read error)"

This is odd as the certbot command ran successfully, generating a fullchain.pem and privkey.pem files. The privkey.pem should not be encrypted, and I haven't needed to decrypt them before.

Has anyone else bumped into problems like this?

---

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [June 7, 2023, 10:22am UTC](https://the.fmsoup.org/t/renewing-letsencrypt-ssl-certificates-cannot-decrypt-the-private-key-file/3598/2 "2023-06-07T10:22:27Z")

</div>

🤦🏽

Normally the process is run via launchd, and it has root privileges.

Running the command from the command line manually, it needs elevated privileges. In other words:

`sudo fmsadmin certificate import "fullchain" --keyfile "privkey" -y`
