← Back to all services
Ssl Certs

Certbot Let's Encrypt SSL Setup

certbot systemctl: certbot.timer (renewal timer)

Automatic HTTPS certificate management. Official Let's Encrypt client.

🔌 Default Ports

80
tcp
HTTP-01 challenge
443
tcp
TLS-ALPN-01 challenge

📦 Installation Command

apt install certbot python3-certbot-nginx python3-certbot-apache

⚙️ Configuration Files

  • /etc/letsencrypt/cli.ini
  • /etc/letsencrypt/renewal/*.conf

📂 Default Directories

  • config: /etc/letsencrypt
  • data: /var/lib/letsencrypt
  • logs: /var/log/letsencrypt
  • certs: /etc/letsencrypt/live
  • renewal: /etc/letsencrypt/renewal

🔐 Default Credentials

Username:N/A
Password:N/A
💡 Certs owned by root. Use --deploy-hook for permissions.

⚠️ Conflicts

N/A Port: Port 80 needed for HTTP-01 challenge

✅ Works With

nginxapache2haproxyany web server

🛡️ Security Notes

Use post-renewal hooks to reload services, monitor expiration, use ECC certs for better performance

❓ Frequently Asked Questions

How to install SSL with Certbot?
Run: sudo certbot --nginx (or --apache) and follow the prompts.
Does Certbot auto-renew?
Yes, certbot installs a systemd timer for automatic renewal.
How to get wildcard certificate?
Use DNS challenge: certbot certonly --manual --preferred-challenges dns -d *.domain.com