On our Cloud Hosting, SSL is automatic. On an Unmanaged VPS you set it up yourself, but it is free and takes about five minutes with Certbot, the official client for Let's Encrypt certificates. Certbot can also edit your Nginx or Apache configuration for you and renew certificates automatically.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
Before you start
- Your domain's A record (and
www) must already point to the VPS: How to Point Your Domain to Your VPS. - Ports 80 and 443 must be open in your firewall. Let's Encrypt checks your domain over port 80.
- Your web server must have a site configured for the domain (an Nginx
server_nameor ApacheServerName). See the LEMP or LAMP guides.
Step 1: Install Certbot
Ubuntu and Debian
sudo apt update # for Nginx sudo apt install -y certbot python3-certbot-nginx # or for Apache sudo apt install -y certbot python3-certbot-apache
AlmaLinux and Rocky Linux
sudo dnf install -y epel-release # for Nginx sudo dnf install -y certbot python3-certbot-nginx # or for Apache sudo dnf install -y certbot python3-certbot-apache mod_ssl
Step 2: Get the certificate
List every name the certificate should cover with -d:
# Nginx sudo certbot --nginx -d example.com -d www.example.com # Apache sudo certbot --apache -d example.com -d www.example.com
The first time, Certbot asks for an email address (optional but useful for account notices) and for you to accept the terms. It then proves you control the domain, installs the certificate in your site configuration, and sets up a redirect from HTTP to HTTPS. If it asks whether to redirect, choose redirect.
Open https://example.com in a browser; you should see the padlock.
Step 3: Make sure renewal is automatic
Let's Encrypt certificates are short-lived (currently 90 days, dropping to 64 days in 2027 and 45 days in 2028), and Let's Encrypt no longer sends expiry reminder emails. Automatic renewal is therefore essential.
# Ubuntu / Debian: a timer is installed automatically systemctl list-timers | grep certbot # AlmaLinux / Rocky: switch the timer on sudo systemctl enable --now certbot-renew.timer # all systems: rehearse a renewal without changing anything sudo certbot renew --dry-run
If the dry run says Congratulations, all simulated renewals succeeded, you are done. The timer runs Certbot regularly; it renews each certificate well before it expires (for today's 90-day certificates, about 30 days before) and reloads the web server.
Managing certificates
| Task | Command |
|---|---|
| List certificates and expiry dates | sudo certbot certificates |
| Add a name to an existing certificate | sudo certbot --nginx --expand -d example.com -d www.example.com -d shop.example.com |
| Delete a certificate you no longer need | sudo certbot delete --cert-name example.com |
| Certificate for a non-web service (web server stopped) | sudo certbot certonly --standalone -d mail.example.com |
Certificate files live in /etc/letsencrypt/live/example.com/: fullchain.pem is the certificate and privkey.pem the private key. Include /etc/letsencrypt in your backups.
Wildcard certificates (*.example.com) need a DNS challenge instead of port 80. Doing it by hand with --manual does not renew automatically, so use a Certbot DNS plugin for your DNS provider if you need wildcards.
Common errors and fixes
| Error | Fix |
|---|---|
Timeout during connect (likely firewall problem) | Port 80 is closed. Allow it in UFW or firewalld and retry. |
DNS problem: NXDOMAIN or wrong IP | The domain doesn't point to this VPS yet. Check with dig +short example.com and wait for DNS to update. Remove any AAAA record that points somewhere else. |
unauthorized / 404 for the challenge file | Another server block is answering for the domain, or the domain is proxied somewhere else. Check server_name and run sudo nginx -t. |
Could not automatically find a matching server block | Add server_name example.com www.example.com; to your Nginx site and reload Nginx. |
too many certificates already issued | You hit a Let's Encrypt rate limit (for example, 5 identical certificates per week). Wait, and use --dry-run while testing. |
Tips
- Certbot's Nginx settings allow only TLS 1.2 and 1.3, which is what you want in 2026.
- If the site uses Cloudflare's proxy, set Cloudflare's SSL/TLS mode to Full (strict) once the certificate is installed.
- WordPress: after enabling HTTPS, make sure Settings → General shows
https://in both address fields.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer