How to set up Let's Encrypt / HTTPS (step-by-step)
Figured I'd write this up since it trips a lot of people up the first time. It's actually pretty painless once you know the steps.
1. Point your domain at your server first. Before you do anything else, make sure your domain's DNS (A record, or AAAA if you're on IPv6) actually points to your server's IP. Let's Encrypt won't issue a cert if it can't verify you own the domain, and DNS propagation can take a bit, so get this sorted first.
2. Install Certbot. This is the go-to client for Let's Encrypt. On Ubuntu/Debian it's just:
sudo apt update && sudo apt install certbot python3-certbot-nginx
(swap python3-certbot-nginx for python3-certbot-apache if you're running Apache). Most other distros have it in their package repos too.
3. Open ports 80 and 443. Domain verification happens over port 80, and HTTPS obviously needs 443. Check your firewall (ufw/firewalld) or your cloud provider's security group settings and make sure both are open.
4. Run Certbot. For Nginx:
sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com
For Apache, same idea with --apache. Certbot handles the verification, grabs the cert, and edits your server config to enable HTTPS + redirect HTTP traffic automatically. It's genuinely one command.
5. Double check it worked. Load https://yourdomain.com and look for the padlock. If you want to be thorough, run sudo certbot certificates or throw your domain into SSL Labs' SSL Test for a full breakdown.
6. Make sure auto-renewal is actually working. These certs expire every 90 days, but Certbot sets up a renewal timer/cron job automatically. Don't just assume it works though — run:
sudo certbot renew --dry-run
and confirm it completes clean. Way better to catch a renewal problem now than find out your cert expired in 3 months.
That's really it. The two things that trip people up 90% of the time are DNS not being ready yet and ports 80/443 being blocked — sort those first and the rest usually just works.