10 Feb 2019

Complete Guide to Configure SSL on Nginx with Let's Encrypt on CentOS/RHEL

Overview

SSL certificates are essential for website security, since browsers mark unprotected sites as unsafe. Commercial certificates cost money, but Let’s Encrypt offers free certificates with a 90-day validity period that can be renewed automatically.

Prerequisites

  • A registered domain name.
  • A CentOS/RHEL (or Ubuntu) server with Nginx installed.

Install Certbot

First, install the EPEL repository for your system version:

RHEL/CentOS 7:

# rpm -Uvh https://dl.fedoraproject.org/pub/epel/7/x86_64/Packages/e/epel-release-7-11.noarch.rpm

RHEL/CentOS 6 (64-bit):

# rpm -Uvh http://download.fedoraproject.org/pub/epel/6/x86_64/epel-release-6-8.noarch.rpm

RHEL/CentOS 6 (32-bit):

# rpm -Uvh http://dl.fedoraproject.org/pub/epel/6/i386/epel-release-6-8.noarch.rpm

Then install Certbot:

# yum install certbot-nginx

Issue the SSL certificate

# certbot --nginx -d example.com -d www.example.com

Replace example.com with your actual domain. You’ll be prompted for an email address and to accept the user agreement.

Certbot verifies domain ownership by placing verification files at http://domain-name/.well-known/acme-challenge/. After verification, choose a redirect option: no redirect (manual Nginx configuration), or automatic redirect configuration with an Nginx reload.

Automatic renewal

Since certificates expire every 90 days, automate renewal via cron:

# crontab -e

Add a job to renew every 30 days at 1:05 AM:

05 01 30 * * /usr/bin/certbot renew --quiet

Test the renewal process without actually renewing:

# certbot renew --dry-run