http://gpp6nwvsps43b3mfacsh433uroo6uyjvvpr6tgj4jh4n5ngxt7rqbvid.onion/posts/openconnect.html
Replace vpn.yyyyy.xyz in the next command by your actual hostname: certbot certonly --standalone --agree-tos --register-unsafely-without-email -d vpn.yyyyy.xyz Your certificate is stored at /etc/letsencrypt/live/vpn.yyyyy.xyz/fullchain.pem , and its private key is stored at /etc/letsencrypt/live/vpn.yyyyy.xyz/privkey.pem . Set up the timer for regular checks for renewal.