4 min read Sep 26, 2026

How to Install a Free SSL Certificate on Your VPS with Certbot

Get a free Let's Encrypt SSL certificate for sites on your VPS with Certbot for Nginx or Apache, switch on HTTPS redirects, confirm auto-renewal and fix common validation errors.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

On our Cloud Hosting, SSL is automatic. On an Unmanaged VPS you set it up yourself, but it is free and takes about five minutes with Certbot, the official client for Let's Encrypt certificates. Certbot can also edit your Nginx or Apache configuration for you and renew certificates automatically.

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

Before you start

  • Your domain's A record (and www) must already point to the VPS: How to Point Your Domain to Your VPS.
  • Ports 80 and 443 must be open in your firewall. Let's Encrypt checks your domain over port 80.
  • Your web server must have a site configured for the domain (an Nginx server_name or Apache ServerName). See the LEMP or LAMP guides.

Step 1: Install Certbot

Ubuntu and Debian

sudo apt update
# for Nginx
sudo apt install -y certbot python3-certbot-nginx
# or for Apache
sudo apt install -y certbot python3-certbot-apache

AlmaLinux and Rocky Linux

sudo dnf install -y epel-release
# for Nginx
sudo dnf install -y certbot python3-certbot-nginx
# or for Apache
sudo dnf install -y certbot python3-certbot-apache mod_ssl

Step 2: Get the certificate

List every name the certificate should cover with -d:

# Nginx
sudo certbot --nginx -d example.com -d www.example.com

# Apache
sudo certbot --apache -d example.com -d www.example.com

The first time, Certbot asks for an email address (optional but useful for account notices) and for you to accept the terms. It then proves you control the domain, installs the certificate in your site configuration, and sets up a redirect from HTTP to HTTPS. If it asks whether to redirect, choose redirect.

Open https://example.com in a browser; you should see the padlock.

Step 3: Make sure renewal is automatic

Let's Encrypt certificates are short-lived (currently 90 days, dropping to 64 days in 2027 and 45 days in 2028), and Let's Encrypt no longer sends expiry reminder emails. Automatic renewal is therefore essential.

# Ubuntu / Debian: a timer is installed automatically
systemctl list-timers | grep certbot

# AlmaLinux / Rocky: switch the timer on
sudo systemctl enable --now certbot-renew.timer

# all systems: rehearse a renewal without changing anything
sudo certbot renew --dry-run

If the dry run says Congratulations, all simulated renewals succeeded, you are done. The timer runs Certbot regularly; it renews each certificate well before it expires (for today's 90-day certificates, about 30 days before) and reloads the web server.

Managing certificates

TaskCommand
List certificates and expiry datessudo certbot certificates
Add a name to an existing certificatesudo certbot --nginx --expand -d example.com -d www.example.com -d shop.example.com
Delete a certificate you no longer needsudo certbot delete --cert-name example.com
Certificate for a non-web service (web server stopped)sudo certbot certonly --standalone -d mail.example.com

Certificate files live in /etc/letsencrypt/live/example.com/: fullchain.pem is the certificate and privkey.pem the private key. Include /etc/letsencrypt in your backups.

Wildcard certificates (*.example.com) need a DNS challenge instead of port 80. Doing it by hand with --manual does not renew automatically, so use a Certbot DNS plugin for your DNS provider if you need wildcards.

Common errors and fixes

ErrorFix
Timeout during connect (likely firewall problem)Port 80 is closed. Allow it in UFW or firewalld and retry.
DNS problem: NXDOMAIN or wrong IPThe domain doesn't point to this VPS yet. Check with dig +short example.com and wait for DNS to update. Remove any AAAA record that points somewhere else.
unauthorized / 404 for the challenge fileAnother server block is answering for the domain, or the domain is proxied somewhere else. Check server_name and run sudo nginx -t.
Could not automatically find a matching server blockAdd server_name example.com www.example.com; to your Nginx site and reload Nginx.
too many certificates already issuedYou hit a Let's Encrypt rate limit (for example, 5 identical certificates per week). Wait, and use --dry-run while testing.

Tips

  • Certbot's Nginx settings allow only TLS 1.2 and 1.3, which is what you want in 2026.
  • If the site uses Cloudflare's proxy, set Cloudflare's SSL/TLS mode to Full (strict) once the certificate is installed.
  • WordPress: after enabling HTTPS, make sure Settings → General shows https:// in both address fields.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer