Skip to content

How to Install a Free Let’s Encrypt SSL Certificate

To install the free SSL Let's Encrypt, set up DNS, ACME, Certbot, Nginx, chain of certificates, redirect and automatic renewal step by step and reversible.

Author Bipida Editorial Team Published
Share this article

Installing a Let's Encrypt certificate is not just executing a command. The domain must be accurate to the server, the challenge must be authenticated from the required path, the private key protected, and the auto-extension must be tested. A certificate that works today but has a broken timer, DNS, or reload can disable the production site in a few weeks.

Quick answer:First check the domain, A/AAAA, web server, and 80/443 ports; then choose the appropriate ACME method. For a typical HTTP-01 domain, it is often simple, but a wildcard requires DNS-01. Install the client from an authentic source, execute the issuance, test the chain and hostname, and at the end of the dry-run renewal and reload service verify.

What do Let's Encrypt and ACME do?

Let's Encrypt is a certificate issuer reference and ACME is a protocol for proving domain control and automating issuance and extension. Being a certificate free does not mean unnecessary operation; DNS, client, credential, timer, key storage, and monitoring are also the responsibility of the server administrator.

Pre-release needs

  • The domain and all the names of the applications are exactly specified.
  • A and AAAA records indicate active trajectory.
  • The server clock and NTP are correct.
  • Port challenge is accessible from the Internet
  • Web server and virtual host correctly identified
  • Backup of config and rollback ready.
  • The owner of the extension and the expiration alert are determined.

Having a broken AAAA record may cause some authentication or users to fail the IPv6 path. Removing the record in a hurry is not a permanent solution; correct the required path or change the DNS knowingly.

Choosing the Challenge method.

HTTP-01

CA reads a temporary file from a specific path on the HTTP domain. Port 80 and route challenge must be accessed from the Internet to the same client. Redirect to HTTPS is usually manageable, but proxy, CDN, or rewrite should not send the challenge path to the wrong login or backend.

DNS-01

DNS control is verified with the TXT record and is required for wildcards. Secure automation requires a DNS API and limited credentials. A token with full account access and maintained in the repository is high risk; design scope, permission, rotation, and location secret.

TLS-ALPN-01

The authentication is done on TLS and port 443, and its support depends on the client and edge architecture. If the load balancer or CDN termination is performed, the challenge should be in the right place. Do not choose the method simply because the other port is closed; check the end-to-end path.

What difference does a wildcard make?

The testimony.*.example.comIt covers the subsoil of a single surface, but is usually called an apex asexample.comIt should be separate on request. A wildcard is issued with DNS-01. If you only have two hostnames, a named certificate may require simpler automation and less DNS credentials.

Get ACME client from a credible source

Certbot is one of the known clients, but the installation method depends on the distribution and package cycle. Do not run unknown scripts with root. Record version, web server plugin or DNS, config path and update method. Two parallel installations of different package managers can blur the timer and path.

Automatic Installer or Certonly?

The web server plugin can automatically change the configuration; cert-only mode only takes the certificate and assigns its connection to Nginx to the administrator. In a simple configuration, automation is convenient. In a complex reverse proxy or managed template, manual modification of the copy gives more control. Check diff config before and after.

Prepare the Nginx before release.

server_nameIf the catch-all redirects or rejects all domains, test the challenge separately.sudo nginx -tCheck the credentials.Nginx configuration for WordPressIt explains the structure of the virtual host.

Firewall and network.

For HTTP-01, the public request must reach port 80; for TLS, path 443 is required. See cloud firewall, host firewall, NAT, and CDN at the same time. Temporary opening of a port for the entire Internet without owner and expiration risks.The Linux firewall guideIt covers flow and external testing.

Production environment release

Select the domain and challenge method explicitly and have a valid operational email for announcements. There is a rate limit for issuing; do not repeat trials and errors with the production domain and use the CA staging environment for testing if supported by the client. Clear the command output for public release.

Full chain and private key.

A web server usually requires a full certificate chain and a corresponding private key. An incomplete supply of the chain may be error-prone on some clients. Private key should not be in Git, a backup without code, or the user's access to the program. Permission should only allow the necessary process and administrator;chmod 777It's not allowed.

Canonical HTTPS Redirect

Once HTTPS is valid, redirect HTTP to the canonical hostname. Redirect should keep the query/path correct and not loop. Behind the CDN or reverse proxy, accept the actual scheme only from a trusted proxy. Trusting the header of any client can create spoofing or looping.

Activate HSTS later.

HSTS forces the browser to use only HTTPS and the certificate error cannot be removed with HTTP. First, maintain the issue, renewal and all the included subdomains. Adding a subdomain or preload is a prolific and long-lasting decision; do not simply copy it from a public snippet.

Technical test after installation

  • Hostname and certificate SANs
  • The time of the system.
  • Full chain and corresponding key
  • Home, asset and endpoint dynamics
  • HTTP redirect and domain alias
  • Multi-client and network connectivity
  • Successful reload and log error-free.

The display of the browser lock alone is not enough. The wrong domain may reach the default certificate and only some SNIs may be corrupted. Test the IPv4 and IPv6 paths separately.

Test the auto-extension the same day.

sudo certbot certificates
sudo certbot renew --dry-run

These are standard for installing Certbot, but if you have another client or container, use the same tool command. dry-run should measure challenge, renewal config and hooks.

Reload after extension

The certificate on the disk may be updated, but the web server process will still provide the previous version in memory. The deploy hook or formal mechanism must check the syntax and reload controlled after successful renewal. Full restart can disconnect without needing.

Certificate in Docker or Load Balancer

Specify where TLS terminates. If the certificate is issued on the host and mounted inside the container, permission, symlink, and reload container are important. Manual copy of the file to the image stale with each renewal. In a managed load balancer, an external export and extension may be made; do not use two sources of truth.

Monitoring is out.

Do not just monitor job renewal; check the certificate that is actually provided from the Internet. alert should take action a few steps before expiration and report the hostname, issuer and expiry.

Common Mistakes

  • Ignoring the AAAA record.
  • Request for wildcard with HTTP-01
  • Save the DNS token in Git
  • Automatically change Nginx without diff checking
  • Certificate delivery instead of full chain
  • Activating HSTS before sustainable renewal
  • Assuming success on the timer without a dry run.
  • File extension without reload service

When do you need special assistance?

If you have a CDN, Docker, wildcard or multiple reverse proxies, challenge and reload may be run at the wrong level.Install and configure the Linux serverIt can implement TLS issuance, secrecy, renewal, monitoring and rollback in line with the actual architecture.

Common Questions

Does free SSL have less security?

The type of authentication and the duration of the certificate varies with other products, but security depends on the key, TLS configuration, patch and correct maintenance; being free is not a weakness of encryption alone.

What's the method for a wildcard?

DNS-01; DNS credentials must have minimum access and secure automation.

Should port 80 always be open?

For HTTP-01, the path should be accessible during authentication; temporary/permanent design should be documented and tested.

Why isn't a new certificate on the site?

The service may not be reloaded, TLS terminate in another layer, or the virtual host may respond incorrectly.

How to Configure a Linux Server Firewall Safely
Set up Linux firewall with inventory flow, default policy, secure SSH, IPv4/IPv6, cloud firewall and external testing; with anti-lock rollback.