How to get a free SSL certificate with Let’s Encrypt

Issue a trusted HTTPS certificate in one command with Certbot, redirect HTTP to HTTPS, and make sure it renews by itself.

1–2 minutes
Hands typing on a laptop keyboard

Let’s Encrypt issues free, trusted certificates that browsers accept everywhere. Certbot is the tool that requests them and configures your web server. Certificates last 90 days and renew automatically.

Before you start: your domain must already point to this server, and port 80 must be open. Let’s Encrypt checks both.

1. Install Certbot

On Ubuntu and Debian with Nginx:

sudo apt install certbot python3-certbot-nginx

On AlmaLinux, Rocky Linux and other RHEL-based systems, enable EPEL first:

sudo dnf install epel-release
sudo dnf install certbot python3-certbot-nginx

For Apache, install python3-certbot-apache instead and use --apache below.

2. Request the certificate

sudo certbot --nginx -d example.com -d www.example.com

Certbot asks for an email address for expiry warnings, then proves you control the domain, installs the certificate and updates your Nginx configuration. When it asks, choose to redirect HTTP to HTTPS.

3. Check renewal

Certbot installs a timer that renews certificates before they expire. Confirm it works:

sudo certbot renew --dry-run
systemctl list-timers | grep certbot

4. Check the result

Visit https://example.com. Then check the details:

curl -sI https://example.com | head -1
sudo certbot certificates

When it fails

Error mentionsUsual cause
DNS problem: NXDOMAINThe domain does not exist in DNS, or has a typo
Timeout during connectPort 80 is blocked by a firewall
Invalid response / 404The domain points to a different server
too many certificates already issuedRate limit hit; wait or use --dry-run while testing

Behind a proxy or CDN, or when port 80 cannot be opened, use a DNS challenge instead, which proves ownership with a TXT record.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.