What is Let's Encrypt?
An SSL certificate puts the padlock and "https" on your site. It scrambles the data between your visitors and your server, so nobody can read it on the way. Let's Encrypt gives these certificates for free. Nginx is a fast web server program. Ubuntu is a popular Linux system.
Before you start
- Your domain must point to your server's IP address.
- Nginx must be installed and running.
- Your server block (the settings section for one site) must have your domain in
server_name.
Steps
- Connect to your server with SSH. Use root, or add
sudobefore each command. - Update the package list:
sudo apt update
- Install Certbot, the tool that gets the certificate, with its Nginx helper:
sudo apt install -y certbot python3-certbot-nginx
- Check your site settings. Open your site file, for example:
sudo nano /etc/nginx/sites-available/example.com
Make sure it has this line, with your own names:
server_name example.com www.example.com;
- Test the settings and reload Nginx:
sudo nginx -t
sudo systemctl reload nginx
- If you use the UFW firewall, allow https:
sudo ufw allow 'Nginx Full'
sudo ufw delete allow 'Nginx HTTP'
The first line opens ports 80 and 443. The second removes the old rule that is no longer needed.
- Ask for your certificate:
sudo certbot --nginx -d example.com -d www.example.com
Certbot asks for your email and to accept the terms. It then offers to redirect http to https. Choose redirect.
- Visit
https://example.comand check the padlock.
Renewal
Certificates last 90 days. On Ubuntu, Certbot sets up automatic renewal for you. Test it:
sudo certbot renew --dry-run
This pretends to renew and shows if anything is wrong. You can also see the timer with systemctl list-timers.
/etc/nginx before you run it.If it fails
- Check your DNS points to this server.
- Check that port 80 is open.
- Check
server_nameis spelled correctly.
Quick recap
- Let's Encrypt gives free SSL certificates.
- Install
certbotandpython3-certbot-nginx. - Run
sudo certbot --nginx -d yourdomain. - Choose to redirect to https.
- Test renewal with
--dry-run.