What is Let's Encrypt?
SSL is a lock for the link between a visitor and your site. A Certificate Authority (CA) is a trusted company that hands out SSL certificates. Let's Encrypt is a free CA run as a non-profit. Its certificates are trusted by all major browsers. They last 90 days, so they must be renewed. Most tools renew them for you.
Before you start
- You own a domain name.
- The domain points to your hosting. DNS is the phone book that connects the name to the server. It must be set correctly.
- Your site opens on plain
http://first.
Way 1: through cPanel (easiest)
- Log in to cPanel.
- Open SSL/TLS Status.
- Find your domain in the list.
- Click Run AutoSSL. This asks for a free certificate and installs it.
- Wait a few minutes. A green padlock icon appears next to the domain.
Whether AutoSSL uses Let's Encrypt depends on the server setup. Ask Hostvento support which provider your plan uses.
Way 2: on your own VPS with Certbot
This way needs root access, so it is for VPS or dedicated server owners. Certbot is a free tool that gets and renews the certificate for you.
- Log in to your server over SSH.
- Install Certbot with your system's package manager. For example on Ubuntu with Apache:
sudo apt install certbot python3-certbot-apache
This installs Certbot and its Apache helper.
sudo certbot --apache -d example.com -d www.example.com
This gets a certificate for both names and sets up Apache to use it.
- Answer the questions. Choose the option to redirect http to https.
- Test the renewal:
sudo certbot renew --dry-run
This pretends to renew, so you know automatic renewal works.
Quick recap
- Let's Encrypt gives free, trusted certificates that last 90 days.
- On cPanel, use SSL/TLS Status and Run AutoSSL.
- On a VPS, use Certbot.
- Make sure the domain points to your server first.
