sorry, I meant to say we need to have certbot recreate ALL the certs after we have done the dns migration to the new server - so it will find the domains on ns11, not ns10. before we have done THAT process, certbot indeed cannot succeed. but after all domains are pointed to the new server, THEN we need to recreate all certs? or will the certs we copied over from the old server still be good? as far as the account problems -- i think I have the explanation. there is only ONE account on the old server. the 'ns11' account on the new server (ns11 is its name after all) must have been created by the auto-installer. (which knew nothing about ns10 of course) then the migration moved over the OLDER account during the LE certs move - but left the new one in place? seems this will always cause these errors, no? and if we delete the NEWER account, we need then to ispconrfig_update.sh --force to have it create the certs for the new server, under the OLD LE account? so maybe... so maybe migration must be followed by some efforts to clean up the LE accounts? and I've read the LE FAQ several times. and again this morning one other question on the migration I will need to migrate emails over no doubt several times to catch stragglers after the dns-repointing. is there a way to have it to do the migration with all prior options (in this case mail ONLY) via command line so I can put it in a cron job?