Home Host a website or app Turn on HTTPS (free certificate)

Turn on HTTPS (free certificate)

Last updated on Sep 16, 2026

Without HTTPS, browsers label your site "Not secure", and anything visitors type can be read in transit. The certificate is free, takes about two minutes, and renews itself.

Before you start

Get the certificate

Connect to your server and run:

sudo apt update
sudo apt install -y certbot python3-certbot-apache
sudo certbot --apache

It asks three things:

  1. Your email address. Used only to warn you if a renewal ever fails. Use a real one you read.
  2. Agree to the terms. Type y.
  3. Which names to secure. It lists the names it found, for example yourcompany.com and www.yourcompany.com. Press Enter to take all of them.

When it finishes it says "Congratulations", and it has already changed your Apache configuration to serve https and to send http visitors to it.

Open https://yourcompany.com. The padlock should be there.

Renewal

Certificates last 90 days and renew themselves. Check that the automatic renewal is in place:

sudo systemctl status certbot.timer

And test a renewal without actually doing one:

sudo certbot renew --dry-run

If it fails

  • "Timeout during connect": port 80 is closed somewhere. The certificate check comes in over port 80, even though it issues a certificate for 443. Recheck both firewalls.
  • "DNS problem: NXDOMAIN": the domain does not point at this server yet. Run nslookup yourcompany.com and wait until it answers with your IP.
  • "Too many certificates already issued": you have retried many times in a week. Wait an hour and use --dry-run while testing.

Managed load balancers

If your site sits behind one of our Load Balancers instead of a single server, the certificate goes on the load balancer, not here. See Add a TLS certificate.