What is Let's Encrypt?
An SSL certificate puts the padlock and "https" on your site. It scrambles the data between your visitors and your server, so nobody can read it on the way. Let's Encrypt gives these certificates for free. Nginx is a fast web server program. CentOS 7 is a Linux system.
Before you start
- Your domain must point to your server's IP address.
- Nginx must be installed and running.
- Ports 80 and 443 must be open in your firewall.
Steps
- Connect to your server with SSH as root.
- Install the EPEL repository, an extra software store:
yum install -y epel-release
- Install Certbot, the tool that gets the certificate, with its Nginx helper:
yum install -y certbot python2-certbot-nginx
- Make sure your Nginx settings have your domain name. In your server block (a settings section for one site), check this line:
server_name example.com www.example.com;
Certbot finds your site by this line.
- Check the settings and reload Nginx:
nginx -t
systemctl reload nginx
- Open the firewall if you use firewalld:
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
- Ask for your certificate:
certbot --nginx -d example.com -d www.example.com
Use your own names. Certbot asks for your email and to accept the terms. It then offers to redirect http visitors to https. Choosing redirect is a good idea.
- Open
https://example.comin your browser and check the padlock.
Renew automatically
These certificates last 90 days. Test that renewal works:
certbot renew --dry-run
This pretends to renew without changing anything. To renew by itself, add a daily job with cron, a timer for tasks:
echo "0 3 * * * root certbot renew --quiet --post-hook 'systemctl reload nginx'" >> /etc/crontab
This runs the check every day at 3 AM.
If it fails
- Check your domain's DNS points to this server.
- Check port 80 is open. Let's Encrypt visits your site on port 80 to check you own it.
- Check
server_nameis spelled correctly.
Quick recap
- Let's Encrypt gives free SSL certificates.
- Install Certbot with the Nginx helper.
- Run
certbot --nginx -d yourdomain. - Choose to redirect to https.
- Set up renewal and test it.