Certbot — Automated Let's Encrypt TLS Certificates
Install and configure Certbot to automatically issue and renew free Let's Encrypt SSL/TLS certificates for web servers.
On this page
What is Certbot?
Certbot is the official Electronic Frontier Foundation (EFF) client for automating the issuance and renewal of free, trusted SSL/TLS certificates from Let's Encrypt using the ACME protocol.
Installation
The recommended installation method across all Linux distributions is via snapd:
sudo apt install -y snapd
sudo snap install core
sudo snap refresh core
sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbotAlternatively, install the standard APT package:
sudo apt install -y certbot python3-certbot-nginxObtaining Certificates
With Nginx Plugin (Automatic config)
Certbot will discover your domain names inside /etc/nginx/sites-available/ and configure SSL directives automatically:
sudo certbot --nginx -d example.com -d www.example.comStandalone Mode (No web server running)
Ideal for mail servers, game servers, or initial setup when port 80 is free:
sudo certbot certonly --standalone -d example.comWebroot Mode (Zero server restart)
Validates using HTTP-01 challenges served from an existing document root:
sudo certbot certonly --webroot -w /var/www/html -d example.comTesting and Automatic Renewal
Let's Encrypt certificates are valid for 90 days. Certbot installs a systemd timer that checks twice daily for certificates expiring within 30 days.
Test the renewal process with a dry run:
sudo certbot renew --dry-runView all managed certificates and expiration dates:
sudo certbot certificatesAlways make sure your domain's A and AAAA DNS records point to your server IP before running Certbot, otherwise the Let's Encrypt HTTP challenge will fail.