Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

First check whether your hosting provider obtains and renews certificates for you. If it does, enable HTTPS using its documented setting. If it does not, and you control the server, use an ACME client such as Certbot to validate your domain, install the certificate, configure renewal, and verify the live HTTPS endpoint.

“SSL certificate” remains a common search term, but modern HTTPS uses SSL/TLS. Certificate issuance is only one part of the job: the certificate must be installed in the service configuration, renewed on schedule, and loaded by the running service.

Choose who will manage the certificate

Let’s Encrypt recommends first asking whether your hosting provider will obtain and manage certificates for you. Many providers do, either automatically or after you turn on an HTTPS setting. Check the provider’s documentation for the exact control and any required domain or DNS setup. If the provider manages renewal, avoid setting up a separate certificate workflow unless its documentation calls for one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you must operate the certificate lifecycle yourself and have the necessary server privileges, you need an ACME client. Let’s Encrypt recommends Certbot for most people in this situation, while noting that other ACME clients are available. Its getting-started guidance was last updated January 23, 2025: Let’s Encrypt: Getting Started.

Choose a validation method that fits your service

The certificate authority must verify control of the domain before issuing a certificate. Choose a method based on what can be reached from the public internet and what access you have to your server or DNS provider; no single method suits every deployment.

Method What it needs Practical consideration
Webroot or web-server plugin A public HTTP site reachable on TCP port 80. With webroot, the server must serve challenge files under /.well-known/acme-challenge. Rules that block or rewrite /.well-known can prevent validation.
Standalone TCP port 80 reachable during validation. Certbot starts a temporary web server, so another server cannot occupy that port during the validation step.
DNS validation Access to the DNS provider, an appropriate Certbot plugin, and configured credentials. The certificate authority does not need an inbound connection to the server. Confirm that a plugin supports your DNS provider and protect its credentials.

These requirements are summarized in Certbot’s usage documentation. HTTP-based methods suit a service with reachable port 80 and a compatible web-server setup. DNS validation can work when inbound access is unavailable, but it adds DNS integration and credential-management responsibilities.

Test issuance against staging before production

Let’s Encrypt recommends testing the ACME workflow against its staging API before requesting a production certificate. A staging certificate is for testing; it is not a replacement for the production certificate users need to reach the service. Keep the staging and production steps distinct, and use the production ACME directory only for the production issuance flow: https://acme-v02.api.letsencrypt.org/directory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Follow the current instructions for your operating system, web server, and Certbot installation method. The Certbot documentation includes platform-specific guidance; commands from different installation methods should not be combined as though they were interchangeable.

Obtain the certificate and install it in the service

Issuing a certificate does not automatically make a service use it. You must configure the web server or application to present the certificate and its corresponding private key. Certbot’s nginx plugin offers two distinct paths, documented in its nginx instructions:

  • sudo certbot --nginx obtains and installs a certificate by editing nginx configuration.
  • sudo certbot certonly --nginx obtains a certificate but leaves configuration changes to you.

These are examples for nginx, not universal commands for every server or installation. If you use certificate-only mode, configure the service with the issued certificate and key using the paths and format appropriate to your stack. Follow the applicable server documentation, then reload or restart the service as required so it serves the new configuration.

Make renewal automatic, then test the full path

Certificates need to be renewed before they expire. Certbot packages include a cron job or systemd timer to attempt renewal, but the scheduler present on your host depends on how Certbot was installed and the platform you use. Confirm that a renewal schedule actually exists rather than assuming it does.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Check the Certbot installation and host configuration to identify whether renewal is scheduled by cron or a systemd timer.
  2. Run sudo certbot renew --dry-run to test the renewal path without treating the test as a production renewal.
  3. Verify that a successful renewal updates the certificate served by your web server or application. Confirm the deployment hook, reload behavior, or other stack-specific step needed to make the running service use the renewed certificate.

Certbot recommends the dry run as a renewal test; its usage documentation describes renewal behavior. A scheduled renewal alone is not enough if the service continues presenting an old certificate after renewal.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Verify the public HTTPS endpoint

After installation, visit the service’s public HTTPS URL in a browser and check that it loads without a certificate warning. HTTPS normally uses TCP port 443, while HTTP normally uses port 80. The service must be configured to accept HTTPS traffic and present a certificate trusted by the client. Certbot’s help and glossary defines HTTPS as HTTP secured with SSL/TLS between browsers and web servers.

A successful page load is a useful smoke test, not a full TLS configuration audit. If the browser reports a problem, check that the DNS name matches the certificate, the service is presenting the intended certificate and chain, HTTPS traffic can reach the server on port 443, and the web-server configuration was reloaded after installation.

Common setup failures and what to check

  • HTTP validation fails: Confirm the site is publicly reachable on port 80 and that requests to /.well-known/acme-challenge are not blocked, redirected incorrectly, or served from the wrong webroot.
  • Standalone validation cannot bind: Another service may already be using port 80. Use a compatible web-server method, arrange a temporary service stop where appropriate, or consider DNS validation.
  • DNS validation fails: Check that the selected Certbot plugin supports your DNS provider, its credentials are configured correctly, and the DNS change is visible to the certificate authority.
  • Certificate issued but browser still warns: Verify that the web server points to the new certificate and key, serves the expected chain, and has reloaded its configuration.
  • Renewal test passes but users see an old certificate later: Check the production scheduler and the service’s post-renewal deployment or reload behavior.

Exact installation commands, file paths, scheduler configuration, and reload steps depend on the operating system, Certbot installation method, DNS provider, and web-server or application stack. Use the current platform-specific instructions for those details rather than assuming one command sequence applies everywhere.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.