10 Feb 2019
Complete Guide to Configure SSL on Nginx with Let's Encrypt on Ubuntu
Overview
Securing your websites with an SSL certificate is now a must for all site admins, to avoid browsers marking them as unsafe. Let’s Encrypt provides free certificates that need renewing every 90 days — though that can be automated.
Prerequisites
- A registered domain name.
- An Ubuntu (or CentOS/RHEL) server with Nginx installed.
Install Certbot
$ sudo apt-get install software-properties-common
$ sudo add-apt-repository universe
$ sudo add-apt-repository ppa:certbot/certbot
$ sudo apt-get update
$ sudo apt-get install python-certbot-nginx
Issue the SSL certificate
$ sudo certbot --nginx -d example.com -d www.example.com
Replace example.com with your actual domain. First-time users need to provide an email
address and agree to the user agreement. Certbot verifies domain ownership by checking
files at http://domain-name/.well-known/acme-challenge. You can then choose no
redirect (manual configuration) or automatic configuration and reload.
Automatic renewal
$ crontab -e
05 01 30 * * /usr/bin/certbot renew --quiet
This renews certificates every 30 days at 1:05 AM. Test the renewal process without renewing:
$ certbot renew --dry-run