Without HTTPS, browsers label your site "Not secure", and anything visitors type can be read in transit. The certificate is free, takes about two minutes, and renews itself.
Before you start
- Your domain already opens your site over http. If not, do Point your domain name at your server first. The certificate is issued by checking your domain, so it cannot be issued before the domain works.
- Port 443 is open in both firewalls, as in Set up your server so a browser can open your site.
Get the certificate
Connect to your server and run:
sudo apt update
sudo apt install -y certbot python3-certbot-apache
sudo certbot --apache
It asks three things:
- Your email address. Used only to warn you if a renewal ever fails. Use a real one you read.
- Agree to the terms. Type
y. - Which names to secure. It lists the names it found, for example
yourcompany.comandwww.yourcompany.com. Press Enter to take all of them.
When it finishes it says "Congratulations", and it has already changed your Apache configuration to serve https and to send http visitors to it.
Open https://yourcompany.com. The padlock should be there.
Renewal
Certificates last 90 days and renew themselves. Check that the automatic renewal is in place:
sudo systemctl status certbot.timer
And test a renewal without actually doing one:
sudo certbot renew --dry-run
If it fails
- "Timeout during connect": port 80 is closed somewhere. The certificate check comes in over port 80, even though it issues a certificate for 443. Recheck both firewalls.
- "DNS problem: NXDOMAIN": the domain does not point at this server yet. Run
nslookup yourcompany.comand wait until it answers with your IP. - "Too many certificates already issued": you have retried many times in a week. Wait an hour and use
--dry-runwhile testing.
Managed load balancers
If your site sits behind one of our Load Balancers instead of a single server, the certificate goes on the load balancer, not here. See Add a TLS certificate.