ssh-keygen -f ~/.ssh/opnsense-letsencrypt
letsencrypt ALL = NOPASSWD: /home/letsencrypt/update-cert.sh fullchain.pem privkey.pem
scp -i ~/opnsense-letsencrypt update-cert.sh letsencrypt@opnsense:.ssh root@opnsense chown root:wheel /home/letsencrypt/update-cert.shssh root@opnsense chmod 500 /home/letsencrypt/update-cert.sh
scp -i ~/opnsense-letsencrypt /etc/letsencrypt/live/<your domain>/{fullchain,privkey}.pem opnsense:.
ssh -i ~/opnsense-letsencrypt letsencrypt@opnsense sudo ./update-cert.sh fullchain.pem privkey.pem