Post Date: October 02, 2018
Last Updated: September 25, 2026
Introduction
Let’s Encrypt provides free SSL/TLS certificates that can be used to secure websites with HTTPS. With Certbot, the certificate installation and Apache configuration can be automated.
This guide explains how to install Certbot, generate a Let’s Encrypt SSL certificate for an Apache-hosted domain, and configure automatic certificate renewal.
Note: The original article uses an older Certbot installation method and a manual cron job. The steps below use the current Certbot approach for supported Linux distributions. Package names and installation methods may vary depending on the operating system.
Prerequisites
Before installing the SSL certificate, ensure that:
- You have root or
sudoaccess to the server. - Apache is installed and running.
- Your domain points to the server’s public IP address.
- Port 80 is accessible for HTTP validation.
- Port 443 is accessible for HTTPS traffic.
- The domain has a valid Apache VirtualHost configuration.
You can verify Apache with:
sudo systemctl status apache2
For RHEL-based systems, the service is commonly:
sudo systemctl status httpd
Implementation
Step 1: Install Certbot
On Ubuntu/Debian systems, install Certbot and the Apache plugin:
sudo apt update sudo apt install certbot python3-certbot-apache
Verify the installation:
certbot --version
Step 2: Generate and Install the SSL Certificate
Replace yourdomain.com with your actual domain:
sudo certbot --apache -d yourdomain.com
For a domain with www support, you can include both names:
sudo certbot --apache -d yourdomain.com -d www.yourdomain.com
Certbot will:
- Validate domain ownership.
- Obtain the SSL certificate.
- Configure Apache to use HTTPS.
- Optionally configure HTTP-to-HTTPS redirection.
After installation, open:
https://yourdomain.com
and verify that the website loads securely.
Step 3: Verify the Certificate
You can check the installed certificate using:
sudo certbot certificates
This displays information such as:
- Certificate name
- Domains
- Expiration date
- Certificate file locations
Step 4: Test Automatic Renewal
Let’s Encrypt certificates are short-lived, so automatic renewal should be configured.
Test the renewal process with:
sudo certbot renew --dry-run
If the test completes successfully, Certbot’s renewal mechanism should be able to renew the certificate when required.
Check the Certbot timer:
systemctl list-timers | grep certbot
On systems using the Certbot systemd timer, no manual cron job is normally required.
Step 5: Verify Apache Configuration
After Certbot modifies the Apache configuration, validate it:
sudo apachectl configtest
Expected output:
Syntax OK
If necessary, reload Apache:
sudo systemctl reload apache2
For RHEL-based systems:
sudo systemctl reload httpd
Troubleshooting
Domain Validation Failed
If Certbot cannot validate the domain, verify that the DNS records point to the correct server:
dig yourdomain.com
Also verify that port 80 is reachable from the internet.
Port 80 or 443 Is Blocked
Check the firewall configuration:
sudo ufw status
If required, allow HTTP and HTTPS:
sudo ufw allow 80/tcp sudo ufw allow 443/tcp
Apache Configuration Error
Before reloading Apache, run:
sudo apachectl configtest
Correct any reported configuration errors before restarting or reloading the service.
Conclusion
Let’s Encrypt provides a free way to secure websites with SSL/TLS certificates. Certbot simplifies the process by handling certificate issuance, Apache configuration, and automated renewal.
The basic installation command is:
sudo certbot --apache -d yourdomain.com
After installation, always test renewal:
sudo certbot renew --dry-run
Regularly verifying certificate renewal helps prevent unexpected SSL expiration and HTTPS-related downtime.
FAQs
1. Is Let’s Encrypt SSL free?
Yes. Let’s Encrypt provides SSL/TLS certificates free of charge.
2. How long is a Let’s Encrypt certificate valid?
Let’s Encrypt certificates are currently issued with a 90-day validity period. Automated renewal is therefore important.
3. Do I need to manually create a cron job for renewal?
Usually, no. Current Certbot installations commonly configure an automated systemd timer or another renewal mechanism. You can verify it with:
systemctl list-timers | grep certbot
Related Articles
- Install SSL Certificate on VestaCP Panel — https://pheonixsolutions.com/blog/install-ssl-certificate-vestacp-panel/
Talk to Our Experts
Need help with SSL, cloud, DevOps, or server management? Our experts can help you find the right solution for your business.
Get in touch with us: Contact our team