Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to add a free SSL certificate to Apache on CentOS 7

This guide shows you how to secure your Apache website with a free Let's Encrypt certificate. It needs root access, so it is for VPS and dedicated server customers.

How-To Guides2 min read8 steps

What is Let's Encrypt?

An SSL certificate puts the padlock and "https" on your site. It scrambles the data between your visitors and your server, so nobody can read it on the way. Let's Encrypt is a service that gives these certificates for free. Apache is a popular web server program. CentOS 7 is a Linux system.

Tip: CentOS 7 is old. Newer systems work in a similar way, but package names may differ.

Before you start

  • Your domain must point to your server's IP address.
  • Apache must be installed and running.
  • Ports 80 and 443 must be open in your firewall.

Steps

  1. Connect to your server with SSH as root.
  2. Install the EPEL repository, which is an extra software store:
yum install -y epel-release
  1. Install Certbot, the tool that gets the certificate, plus its Apache helper:
yum install -y certbot python2-certbot-apache mod_ssl

mod_ssl lets Apache speak https.

  1. Make sure your site has a virtual host, which is a settings block with your domain in ServerName. For example, in /etc/httpd/conf.d/example.com.conf:
<VirtualHost *:80>
    ServerName example.com
    ServerAlias www.example.com
    DocumentRoot /var/www/html
</VirtualHost>
  1. Check the settings and reload Apache:
apachectl configtest
systemctl reload httpd
  1. Open the firewall if you use firewalld:
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
  1. Ask for your certificate:
certbot --apache -d example.com -d www.example.com

Replace the names with your own. Certbot asks for your email and to accept the terms. It may ask if you want to send all visitors to https. Choosing redirect is a good idea.

  1. Visit https://example.com and look for the padlock.

Renew automatically

Let's Encrypt certificates last 90 days. Test that renewal works:

certbot renew --dry-run

This pretends to renew without changing anything. Then add a daily job with cron, which is a timer for tasks:

echo "0 3 * * * root certbot renew --quiet --post-hook 'systemctl reload httpd'" >> /etc/crontab

This runs the check every day at 3 AM.

Warning: Back up your Apache settings before running Certbot. It edits them.

Quick recap

  • Let's Encrypt gives free SSL certificates.
  • Install Certbot and mod_ssl.
  • Run certbot --apache -d yourdomain.
  • Choose to redirect to https.
  • Set up automatic renewal and test it.