# Steps for renewing Grafana SSL 

1. Renew SSL with certbot 

2. Backup old ssl certs located at /etc/grafana

Example;
    create backup folder for SSL certs. The naming convention used for creating the folder is the backup-<current-date>

        `mkdir backup-01-01-2023`

    Copy old certs to backup folder

        `mv *.pem backup-01-01-2023/`


3. Copy new SSL certs to the /etc/grafana directory

    Run:

        `cp /etc/letsencrypt/live/monitor.snwolley.com-0001/*.pem /etc/grafana`

4. Change owership of certs to grafana 

    Run:

        `chown root:grafana /etc/grafana/*.pem`

5. Change permissions of SSL certs in /etc/grafana to 640

    Run:

        `chmod 640 /etc/grafana/*.pem`

6. Restart Grafana server 

    Run:

        `systemctl restart grafana-server`

7. Confirm grafana server status. **Troubleshoot issues by checking logs in /var/log/grafana**

    Run:
    
        `systemctl status grafana-server`


