How to Install Let’s Encrypt SSL

Post Date: October 02, 2018
Last Updated: September 25, 2026

Introduction

Let’s Encrypt provides free SSL/TLS certificates that can be used to secure websites with HTTPS. With Certbot, the certificate installation and Apache configuration can be automated.

This guide explains how to install Certbot, generate a Let’s Encrypt SSL certificate for an Apache-hosted domain, and configure automatic certificate renewal.

Note: The original article uses an older Certbot installation method and a manual cron job. The steps below use the current Certbot approach for supported Linux distributions. Package names and installation methods may vary depending on the operating system.

Prerequisites

Before installing the SSL certificate, ensure that:

  • You have root or sudo access to the server.
  • Apache is installed and running.
  • Your domain points to the server’s public IP address.
  • Port 80 is accessible for HTTP validation.
  • Port 443 is accessible for HTTPS traffic.
  • The domain has a valid Apache VirtualHost configuration.

You can verify Apache with:

sudo systemctl status apache2

For RHEL-based systems, the service is commonly:

sudo systemctl status httpd

Implementation

Step 1: Install Certbot

On Ubuntu/Debian systems, install Certbot and the Apache plugin:

sudo apt update
sudo apt install certbot python3-certbot-apache

Verify the installation:

certbot --version

Step 2: Generate and Install the SSL Certificate

Replace yourdomain.com with your actual domain:

sudo certbot --apache -d yourdomain.com

For a domain with www support, you can include both names:

sudo certbot --apache -d yourdomain.com -d www.yourdomain.com

Certbot will:

  1. Validate domain ownership.
  2. Obtain the SSL certificate.
  3. Configure Apache to use HTTPS.
  4. Optionally configure HTTP-to-HTTPS redirection.

After installation, open:

https://yourdomain.com

and verify that the website loads securely.

Step 3: Verify the Certificate

You can check the installed certificate using:

sudo certbot certificates

This displays information such as:

  • Certificate name
  • Domains
  • Expiration date
  • Certificate file locations

Step 4: Test Automatic Renewal

Let’s Encrypt certificates are short-lived, so automatic renewal should be configured.

Test the renewal process with:

sudo certbot renew --dry-run

If the test completes successfully, Certbot’s renewal mechanism should be able to renew the certificate when required.

Check the Certbot timer:

systemctl list-timers | grep certbot

On systems using the Certbot systemd timer, no manual cron job is normally required.

Step 5: Verify Apache Configuration

After Certbot modifies the Apache configuration, validate it:

sudo apachectl configtest

Expected output:

Syntax OK

If necessary, reload Apache:

sudo systemctl reload apache2

For RHEL-based systems:

sudo systemctl reload httpd

Troubleshooting

Domain Validation Failed

If Certbot cannot validate the domain, verify that the DNS records point to the correct server:

dig yourdomain.com

Also verify that port 80 is reachable from the internet.

Port 80 or 443 Is Blocked

Check the firewall configuration:

sudo ufw status

If required, allow HTTP and HTTPS:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

Apache Configuration Error

Before reloading Apache, run:

sudo apachectl configtest

Correct any reported configuration errors before restarting or reloading the service.

Conclusion

Let’s Encrypt provides a free way to secure websites with SSL/TLS certificates. Certbot simplifies the process by handling certificate issuance, Apache configuration, and automated renewal.

The basic installation command is:

sudo certbot --apache -d yourdomain.com

After installation, always test renewal:

sudo certbot renew --dry-run

Regularly verifying certificate renewal helps prevent unexpected SSL expiration and HTTPS-related downtime.

FAQs

1. Is Let’s Encrypt SSL free?

Yes. Let’s Encrypt provides SSL/TLS certificates free of charge.

2. How long is a Let’s Encrypt certificate valid?

Let’s Encrypt certificates are currently issued with a 90-day validity period. Automated renewal is therefore important.

3. Do I need to manually create a cron job for renewal?

Usually, no. Current Certbot installations commonly configure an automated systemd timer or another renewal mechanism. You can verify it with:

systemctl list-timers | grep certbot

Talk to Our Experts

Need help with SSL, cloud, DevOps, or server management? Our experts can help you find the right solution for your business.

Get in touch with us: Contact our team

admin

Our team has expertise across software and web development, WordPress, e-commerce, mobile applications, UI/UX, cloud and infrastructure, DevOps, CI/CD, API integration, security, testing, automation, and technical support. The team also works with AI-based software solutions, LLMs, AI workflows, AI agents, and intelligent application development to help businesses automate processes and build smarter digital solutions. We focus on developing, deploying, maintaining, and optimising secure, scalable, and reliable technology solutions while helping businesses adopt modern technologies and drive digital transformation.

Leave a Reply

Scroll to Top