http://certbot.iykpqm7jiradoeezzkhj7c4b33g4hbgfwelht2evxxeicbpjy44c7ead.onion/faq
However, you need to provide writable paths for Certbot's working directories either by ensuring that /etc/letsencrypt/ , /var/log/letsencrypt/ , /var/lib/letsencrypt/ are writable, or by picking different directories with the --config-dir , --logs-dir , and --work-dir flags. The standalone plugin requires root to bind port 80 or 443, although on Linux you could also grant CAP_NET_BIND_SERVICE to the relevant user.