--- /dev/null
+#!/bin/bash
+cert_dir=/etc/cert-live.fsf.org
+mkdir -p $cert_dir
+cd $cert_dir
+rsync -e 'ssh -o StrictHostKeyChecking=accept-new' -tL --perms streamserver0p.fsf.org:/etc/letsencrypt/live/streamserver0p.fsf.org/{fullchain,privkey}.pem .