10 Feb 2019

Complete Guide to Configure SSL on Nginx with Let's Encrypt on Ubuntu

Overview

Securing your websites with an SSL certificate is now a must for all site admins, to avoid browsers marking them as unsafe. Let’s Encrypt provides free certificates that need renewing every 90 days — though that can be automated.

Prerequisites

  • A registered domain name.
  • An Ubuntu (or CentOS/RHEL) server with Nginx installed.

Install Certbot

$ sudo apt-get install software-properties-common
$ sudo add-apt-repository universe
$ sudo add-apt-repository ppa:certbot/certbot
$ sudo apt-get update
$ sudo apt-get install python-certbot-nginx

Issue the SSL certificate

$ sudo certbot --nginx -d example.com -d www.example.com

Replace example.com with your actual domain. First-time users need to provide an email address and agree to the user agreement. Certbot verifies domain ownership by checking files at http://domain-name/.well-known/acme-challenge. You can then choose no redirect (manual configuration) or automatic configuration and reload.

Automatic renewal

$ crontab -e
05 01 30 * * /usr/bin/certbot renew --quiet

This renews certificates every 30 days at 1:05 AM. Test the renewal process without renewing:

$ certbot renew --dry-run