Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to add a free SSL certificate to Nginx on Ubuntu 20.04

This guide shows you how to secure your Nginx website with a free Let's Encrypt certificate. It needs root access, so it is for VPS and dedicated server customers.

How-To Guides2 min read8 steps

What is Let's Encrypt?

An SSL certificate puts the padlock and "https" on your site. It scrambles the data between your visitors and your server, so nobody can read it on the way. Let's Encrypt gives these certificates for free. Nginx is a fast web server program. Ubuntu is a popular Linux system.

Tip: Ubuntu 20.04 is getting old. Newer Ubuntu versions use almost the same steps.

Before you start

  • Your domain must point to your server's IP address.
  • Nginx must be installed and running.
  • Your server block (the settings section for one site) must have your domain in server_name.

Steps

  1. Connect to your server with SSH. Use root, or add sudo before each command.
  2. Update the package list:
sudo apt update
  1. Install Certbot, the tool that gets the certificate, with its Nginx helper:
sudo apt install -y certbot python3-certbot-nginx
  1. Check your site settings. Open your site file, for example:
sudo nano /etc/nginx/sites-available/example.com

Make sure it has this line, with your own names:

server_name example.com www.example.com;
  1. Test the settings and reload Nginx:
sudo nginx -t
sudo systemctl reload nginx
  1. If you use the UFW firewall, allow https:
sudo ufw allow 'Nginx Full'
sudo ufw delete allow 'Nginx HTTP'

The first line opens ports 80 and 443. The second removes the old rule that is no longer needed.

  1. Ask for your certificate:
sudo certbot --nginx -d example.com -d www.example.com

Certbot asks for your email and to accept the terms. It then offers to redirect http to https. Choose redirect.

  1. Visit https://example.com and check the padlock.

Renewal

Certificates last 90 days. On Ubuntu, Certbot sets up automatic renewal for you. Test it:

sudo certbot renew --dry-run

This pretends to renew and shows if anything is wrong. You can also see the timer with systemctl list-timers.

Warning: Certbot edits your Nginx files. Back up /etc/nginx before you run it.

If it fails

  • Check your DNS points to this server.
  • Check that port 80 is open.
  • Check server_name is spelled correctly.

Quick recap

  • Let's Encrypt gives free SSL certificates.
  • Install certbot and python3-certbot-nginx.
  • Run sudo certbot --nginx -d yourdomain.
  • Choose to redirect to https.
  • Test renewal with --dry-run.