Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Install Apache and Add a Free Let's Encrypt SSL

This guide shows you how to install the Apache web server on Ubuntu and secure it with a free Let's Encrypt certificate. You need root access, so it suits VPS and dedicated server customers.

SSL and Security2 min read12 steps1 screenshots

What are these things?

Apache is a program that shows your website to visitors. An SSL certificate is a digital badge that makes the connection safe, so the address starts with HTTPS. Let's Encrypt is a free service that gives out these certificates. Certbot is a helper tool that gets and installs them for you.

Before you start

  • Your domain name must point to your server's IP address. Without this, Let's Encrypt cannot check that you own the domain.
    Creating DNS Record
  • Ports 80 and 443 must be open in your firewall.

Steps

  1. Log in to your server with SSH.
  2. Update the package list:
    sudo apt update
    This refreshes the list of software you can install.
  3. Install Apache:
    sudo apt install apache2 -y
  4. Check that Apache is running:
    sudo systemctl status apache2
    You should see the word "active".
  5. Open your server IP in a browser. You should see the Apache welcome page.
  6. Create a virtual host file. A virtual host tells Apache which folder belongs to which domain:
    sudo nano /etc/apache2/sites-available/yourdomain.com.conf
  7. Paste this and change the names to yours:
    <VirtualHost *:80>
      ServerName yourdomain.com
      ServerAlias www.yourdomain.com
      DocumentRoot /var/www/yourdomain.com
    </VirtualHost>
  8. Create the folder and turn the site on:
    sudo mkdir -p /var/www/yourdomain.com
    sudo a2ensite yourdomain.com.conf
    sudo systemctl reload apache2
  9. Install Certbot:
    sudo apt install certbot python3-certbot-apache -y
  10. Run Certbot:
    sudo certbot --apache -d yourdomain.com -d www.yourdomain.com
    Type your email address and agree to the terms when asked. Choose to redirect HTTP to HTTPS if offered.
  11. Visit https://yourdomain.com and look for the padlock.
  12. Test automatic renewal:
    sudo certbot renew --dry-run
    Let's Encrypt certificates last a short time, so renewal must work.
Tip: These commands are for Ubuntu and similar systems. Other systems use different commands but the idea is the same.

Quick recap

  • Install Apache, then create a virtual host for your domain.
  • Point your domain to the server first.
  • Install Certbot and run it with the --apache option.
  • Test renewal with certbot renew --dry-run.