{"id":2588,"date":"2018-10-02T09:15:08","date_gmt":"2018-10-02T03:45:08","guid":{"rendered":"https:\/\/pheonixsolutions.com\/blog\/?p=2588"},"modified":"2026-09-25T21:13:43","modified_gmt":"2026-09-25T15:43:43","slug":"how-to-install-lets-encrypt-ssl","status":"publish","type":"post","link":"https:\/\/pheonixsolutions.com\/blog\/how-to-install-lets-encrypt-ssl\/","title":{"rendered":"How to Install Let\u2019s Encrypt SSL"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Post Date:<\/strong> October 02, 2018<br><strong>Last Updated:<\/strong> September 25, 2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s Encrypt provides free SSL\/TLS certificates that can be used to secure websites with HTTPS. With Certbot, the certificate installation and Apache configuration can be automated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide explains how to install Certbot, generate a Let\u2019s Encrypt SSL certificate for an Apache-hosted domain, and configure automatic certificate renewal.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> The original article uses an older Certbot installation method and a manual cron job. The steps below use the current Certbot approach for supported Linux distributions. Package names and installation methods may vary depending on the operating system.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before installing the SSL certificate, ensure that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You have root or <code>sudo<\/code> access to the server.<\/li>\n\n\n\n<li>Apache is installed and running.<\/li>\n\n\n\n<li>Your domain points to the server&#8217;s public IP address.<\/li>\n\n\n\n<li>Port <strong>80<\/strong> is accessible for HTTP validation.<\/li>\n\n\n\n<li>Port <strong>443<\/strong> is accessible for HTTPS traffic.<\/li>\n\n\n\n<li>The domain has a valid Apache VirtualHost configuration.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">You can verify Apache with:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo systemctl status apache2<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For RHEL-based systems, the service is commonly:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo systemctl status httpd<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Implementation<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: Install Certbot<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On Ubuntu\/Debian systems, install Certbot and the Apache plugin:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo apt update\nsudo apt install certbot python3-certbot-apache<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Verify the installation:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">certbot --version<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: Generate and Install the SSL Certificate<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Replace <code>yourdomain.com<\/code> with your actual domain:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo certbot --apache -d yourdomain.com<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For a domain with <code>www<\/code> support, you can include both names:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo certbot --apache -d yourdomain.com -d www.yourdomain.com<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Certbot will:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Validate domain ownership.<\/li>\n\n\n\n<li>Obtain the SSL certificate.<\/li>\n\n\n\n<li>Configure Apache to use HTTPS.<\/li>\n\n\n\n<li>Optionally configure HTTP-to-HTTPS redirection.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">After installation, open:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">https:\/\/yourdomain.com<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">and verify that the website loads securely.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: Verify the Certificate<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can check the installed certificate using:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo certbot certificates<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This displays information such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Certificate name<\/li>\n\n\n\n<li>Domains<\/li>\n\n\n\n<li>Expiration date<\/li>\n\n\n\n<li>Certificate file locations<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4: Test Automatic Renewal<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Let&#8217;s Encrypt certificates are short-lived, so automatic renewal should be configured.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Test the renewal process with:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo certbot renew --dry-run<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the test completes successfully, Certbot&#8217;s renewal mechanism should be able to renew the certificate when required.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check the Certbot timer:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">systemctl list-timers | grep certbot<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">On systems using the Certbot systemd timer, no manual cron job is normally required.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 5: Verify Apache Configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After Certbot modifies the Apache configuration, validate it:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo apachectl configtest<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Expected output:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">Syntax OK<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If necessary, reload Apache:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo systemctl reload apache2<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For RHEL-based systems:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo systemctl reload httpd<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Domain Validation Failed<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If Certbot cannot validate the domain, verify that the DNS records point to the correct server:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">dig yourdomain.com<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Also verify that port 80 is reachable from the internet.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Port 80 or 443 Is Blocked<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check the firewall configuration:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo ufw status<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If required, allow HTTP and HTTPS:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo ufw allow 80\/tcp\nsudo ufw allow 443\/tcp<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Apache Configuration Error<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before reloading Apache, run:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo apachectl configtest<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Correct any reported configuration errors before restarting or reloading the service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s Encrypt provides a free way to secure websites with SSL\/TLS certificates. Certbot simplifies the process by handling certificate issuance, Apache configuration, and automated renewal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The basic installation command is:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo certbot --apache -d yourdomain.com<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">After installation, always test renewal:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo certbot renew --dry-run<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Regularly verifying certificate renewal helps prevent unexpected SSL expiration and HTTPS-related downtime.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQs<\/h2>\n\n\n\n<h4 class=\"wp-block-heading\">1. Is Let\u2019s Encrypt SSL free?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. Let\u2019s Encrypt provides SSL\/TLS certificates free of charge.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. How long is a Let\u2019s Encrypt certificate valid?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s Encrypt certificates are currently issued with a <strong>90-day validity period<\/strong>. Automated renewal is therefore important.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3. Do I need to manually create a cron job for renewal?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Usually, no. Current Certbot installations commonly configure an automated systemd timer or another renewal mechanism. You can verify it with:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">systemctl list-timers | grep certbot<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Related Articles<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Install SSL Certificate on VestaCP Panel<\/strong> \u2014 <a href=\"https:\/\/pheonixsolutions.com\/blog\/install-ssl-certificate-vestacp-panel\/\">https:\/\/pheonixsolutions.com\/blog\/install-ssl-certificate-vestacp-panel\/<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Talk to Our Experts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Need help with SSL, cloud, DevOps, or server management? Our experts can help you find the right solution for your business.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Get in touch with us:<\/strong> <a href=\"https:\/\/pheonixsolutions.com\/contact\">Contact our team<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Post Date: October 02, 2018Last Updated: September 25, 2026 Introduction Let\u2019s Encrypt provides free SSL\/TLS certificates that can be used [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1024],"tags":[425,277,206],"class_list":["post-2588","post","type-post","status-publish","format-standard","hentry","category-security","tag-lets-encrpyt-ssl","tag-ssl","tag-ssl-certificate-installation","psol-cat-security"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/phn2x7-FK","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/2588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/comments?post=2588"}],"version-history":[{"count":1,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/2588\/revisions"}],"predecessor-version":[{"id":11930,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/2588\/revisions\/11930"}],"wp:attachment":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/media?parent=2588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/categories?post=2588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/tags?post=2588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}