Complete Guide to Configure SSL on Nginx with Let's Encrypt on CentOS/RHEL
Overview
SSL certificates are essential for website security, since browsers mark unprotected sites as unsafe. Commercial certificates cost money, but Let’s Encrypt offers free certificates with a 90-day validity period that can be renewed automatically.
Prerequisites
- A registered domain name.
- A CentOS/RHEL (or Ubuntu) server with Nginx installed.
Install Certbot
First, install the EPEL repository for your system version:
RHEL/CentOS 7:
# rpm -Uvh https://dl.fedoraproject.org/pub/epel/7/x86_64/Packages/e/epel-release-7-11.noarch.rpm
RHEL/CentOS 6 (64-bit):
# rpm -Uvh http://download.fedoraproject.org/pub/epel/6/x86_64/epel-release-6-8.noarch.rpm
RHEL/CentOS 6 (32-bit):
# rpm -Uvh http://dl.fedoraproject.org/pub/epel/6/i386/epel-release-6-8.noarch.rpm
Then install Certbot:
# yum install certbot-nginx
Issue the SSL certificate
# certbot --nginx -d example.com -d www.example.com
Replace example.com with your actual domain. You’ll be prompted for an email address
and to accept the user agreement.
Certbot verifies domain ownership by placing verification files at
http://domain-name/.well-known/acme-challenge/. After verification, choose a redirect
option: no redirect (manual Nginx configuration), or automatic redirect configuration
with an Nginx reload.
Automatic renewal
Since certificates expire every 90 days, automate renewal via cron:
# crontab -e
Add a job to renew every 30 days at 1:05 AM:
05 01 30 * * /usr/bin/certbot renew --quiet
Test the renewal process without actually renewing:
# certbot renew --dry-run