For people that want something much smaller (dependency-wise), I can recommend letsencrypt.sh which – together with cron – achieves the same goal: https://github.com/lukas2511/letsencrypt.sh
letsencrypt.sh is great. It has easy support for existing CSRs and can do dns-01 verification (i.e. making sure you control the domain via a DNS secret rather an http get path/secret). I wrote up a usage tutorial for the latter with Route53 here https://blog.boldlisting.com/free-ssl-certificates-without-p...