Let’s Encrypt issues free, trusted certificates that browsers accept everywhere. Certbot is the tool that requests them and configures your web server. Certificates last 90 days and renew automatically.
Before you start: your domain must already point to this server, and port 80 must be open. Let’s Encrypt checks both.
1. Install Certbot
On Ubuntu and Debian with Nginx:
sudo apt install certbot python3-certbot-nginx
On AlmaLinux, Rocky Linux and other RHEL-based systems, enable EPEL first:
sudo dnf install epel-release
sudo dnf install certbot python3-certbot-nginx
For Apache, install python3-certbot-apache instead and use --apache below.
2. Request the certificate
sudo certbot --nginx -d example.com -d www.example.com
Certbot asks for an email address for expiry warnings, then proves you control the domain, installs the certificate and updates your Nginx configuration. When it asks, choose to redirect HTTP to HTTPS.
3. Check renewal
Certbot installs a timer that renews certificates before they expire. Confirm it works:
sudo certbot renew --dry-run
systemctl list-timers | grep certbot
4. Check the result
Visit https://example.com. Then check the details:
curl -sI https://example.com | head -1
sudo certbot certificates
When it fails
| Error mentions | Usual cause |
|---|---|
| DNS problem: NXDOMAIN | The domain does not exist in DNS, or has a typo |
| Timeout during connect | Port 80 is blocked by a firewall |
| Invalid response / 404 | The domain points to a different server |
| too many certificates already issued | Rate limit hit; wait or use --dry-run while testing |
Behind a proxy or CDN, or when port 80 cannot be opened, use a DNS challenge instead, which proves ownership with a TXT record.
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.
