What is Let's Encrypt?
An SSL certificate puts the padlock and "https" on your site. It scrambles the data between your visitors and your server, so nobody can read it on the way. Let's Encrypt is a service that gives these certificates for free. Apache is a popular web server program. CentOS 7 is a Linux system.
Before you start
- Your domain must point to your server's IP address.
- Apache must be installed and running.
- Ports 80 and 443 must be open in your firewall.
Steps
- Connect to your server with SSH as root.
- Install the EPEL repository, which is an extra software store:
yum install -y epel-release
- Install Certbot, the tool that gets the certificate, plus its Apache helper:
yum install -y certbot python2-certbot-apache mod_ssl
mod_ssl lets Apache speak https.
- Make sure your site has a virtual host, which is a settings block with your domain in
ServerName. For example, in/etc/httpd/conf.d/example.com.conf:
<VirtualHost *:80>
ServerName example.com
ServerAlias www.example.com
DocumentRoot /var/www/html
</VirtualHost>
- Check the settings and reload Apache:
apachectl configtest
systemctl reload httpd
- Open the firewall if you use firewalld:
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
- Ask for your certificate:
certbot --apache -d example.com -d www.example.com
Replace the names with your own. Certbot asks for your email and to accept the terms. It may ask if you want to send all visitors to https. Choosing redirect is a good idea.
- Visit
https://example.comand look for the padlock.
Renew automatically
Let's Encrypt certificates last 90 days. Test that renewal works:
certbot renew --dry-run
This pretends to renew without changing anything. Then add a daily job with cron, which is a timer for tasks:
echo "0 3 * * * root certbot renew --quiet --post-hook 'systemctl reload httpd'" >> /etc/crontab
This runs the check every day at 3 AM.
Quick recap
- Let's Encrypt gives free SSL certificates.
- Install Certbot and
mod_ssl. - Run
certbot --apache -d yourdomain. - Choose to redirect to https.
- Set up automatic renewal and test it.