Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to add a free SSL certificate to Nginx on CentOS 7

This guide shows you how to secure your Nginx website with a free Let's Encrypt certificate. It needs root access, so it is for VPS and dedicated server customers.

How-To Guides2 min read8 steps

What is Let's Encrypt?

An SSL certificate puts the padlock and "https" on your site. It scrambles the data between your visitors and your server, so nobody can read it on the way. Let's Encrypt gives these certificates for free. Nginx is a fast web server program. CentOS 7 is a Linux system.

Tip: CentOS 7 is old. Newer systems work in a similar way, but package names may differ.

Before you start

  • Your domain must point to your server's IP address.
  • Nginx must be installed and running.
  • Ports 80 and 443 must be open in your firewall.

Steps

  1. Connect to your server with SSH as root.
  2. Install the EPEL repository, an extra software store:
yum install -y epel-release
  1. Install Certbot, the tool that gets the certificate, with its Nginx helper:
yum install -y certbot python2-certbot-nginx
  1. Make sure your Nginx settings have your domain name. In your server block (a settings section for one site), check this line:
server_name example.com www.example.com;

Certbot finds your site by this line.

  1. Check the settings and reload Nginx:
nginx -t
systemctl reload nginx
  1. Open the firewall if you use firewalld:
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
  1. Ask for your certificate:
certbot --nginx -d example.com -d www.example.com

Use your own names. Certbot asks for your email and to accept the terms. It then offers to redirect http visitors to https. Choosing redirect is a good idea.

  1. Open https://example.com in your browser and check the padlock.

Renew automatically

These certificates last 90 days. Test that renewal works:

certbot renew --dry-run

This pretends to renew without changing anything. To renew by itself, add a daily job with cron, a timer for tasks:

echo "0 3 * * * root certbot renew --quiet --post-hook 'systemctl reload nginx'" >> /etc/crontab

This runs the check every day at 3 AM.

Warning: Back up your Nginx settings before running Certbot, because it edits them.

If it fails

  • Check your domain's DNS points to this server.
  • Check port 80 is open. Let's Encrypt visits your site on port 80 to check you own it.
  • Check server_name is spelled correctly.

Quick recap

  • Let's Encrypt gives free SSL certificates.
  • Install Certbot with the Nginx helper.
  • Run certbot --nginx -d yourdomain.
  • Choose to redirect to https.
  • Set up renewal and test it.