In case you need an automated update of your let's encrypt certs:
make a script (best: put in in cron)
#!/bin/bash
logfile="/var/log/renew_$(date -Is).log"
echo "$(date +%T):" >$logfile
/usr/bin/certbot renew --quiet
cp /etc/letsencrypt/live/YOURDOMAIN.COM/{cert,chain,privkey}.pem /opt/tomcat/latest/conf/
chown tomcat:tomcat /opt/tomcat/latest/conf/*.pem