Let's Encrypt gives you free, trusted SSL certificates, so your website runs over HTTPS with the padlock in the browser. Certbot is the official tool for requesting them and renewing them automatically. This guide covers websites run with Nginx or Apache directly on your VPS.
It works on every operating system we offer: Ubuntu 22.04, 24.04 and 26.04, Debian 12 and 13, AlmaLinux 8, 9 and 10, and Rocky Linux 9 and 10.
Using Docker? If your apps run in Docker, it's usually easier to let a reverse proxy such as Caddy or Nginx Proxy Manager handle certificates for you. Our Docker app guides include this.
Before you start
- A website already set up in Nginx or Apache, answering on port 80 for your domain.
- Your domain's A record (and
www, if you use it) pointing to your VPS IP address. - Ports 80 and 443 open in your firewall. Let's Encrypt checks your domain over port 80.
- SSH access as root or as a user with sudo rights. If you're logged in as root, you can leave
sudooff the commands.
Throughout this guide, replace example.co.nz with your own domain.
Step 1: Install Certbot
Ubuntu/Debian, for Nginx:
sudo apt update
sudo apt install -y certbot python3-certbot-nginx
Or for Apache:
sudo apt update
sudo apt install -y certbot python3-certbot-apache
AlmaLinux/Rocky (Certbot comes from the EPEL repository), for Nginx:
sudo dnf install -y epel-release
sudo dnf install -y certbot python3-certbot-nginx
Or for Apache:
sudo dnf install -y epel-release
sudo dnf install -y certbot python3-certbot-apache mod_ssl
Step 2: Open the firewall
Ubuntu/Debian with UFW enabled:
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
AlmaLinux/Rocky with firewalld:
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --reload
Step 3: Get your certificate
Certbot finds your site's configuration, gets the certificate and sets up HTTPS for you.
Nginx:
sudo certbot --nginx -d example.co.nz -d www.example.co.nz
Apache:
sudo certbot --apache -d example.co.nz -d www.example.co.nz
The first time, Certbot asks for your email address (for expiry warnings) and asks you to agree to the terms. When it finishes, open https://example.co.nz to check the padlock shows.
Certbot also sets your site to redirect HTTP to HTTPS. You can add more domains at any time by running the same command with extra -d options.
Step 4: Check automatic renewal
Let's Encrypt certificates last 90 days, and Certbot renews them automatically before they expire.
Ubuntu/Debian: renewal is set up for you when you install Certbot.
AlmaLinux/Rocky: turn on the renewal timer yourself:
sudo systemctl enable --now certbot-renew.timer
On all systems, test that renewal works:
sudo certbot renew --dry-run
If this finishes without errors, your certificates will renew on their own.
No web server? Use standalone mode
If you need a certificate for something other than a website, such as a mail server or an app with its own web server, Certbot can run a temporary web server of its own. Port 80 must be free while it runs:
sudo certbot certonly --standalone -d mail.example.co.nz
The certificate files are saved in /etc/letsencrypt/live/mail.example.co.nz/. Point your app at fullchain.pem (certificate) and privkey.pem (private key).
Useful Certbot commands
sudo certbot certificates: list your certificates and when they expiresudo certbot renew: renew any certificates close to expirysudo certbot delete --cert-name example.co.nz: remove a certificate you no longer need
Troubleshooting
- "Challenge failed" or "Connection refused": Let's Encrypt couldn't reach your site on port 80. Check that the domain's A record points to this VPS, that port 80 is open, and that your web server is running.
- "Could not automatically find a matching server block": your Nginx or Apache configuration needs a
server_name(Nginx) orServerName(Apache) line matching the domain. Add it, reload the web server and try again. - "Too many certificates already issued": Let's Encrypt limits how many certificates you can request for the same domain each week. Wait and try again later, and use
--dry-runwhen testing. - DNS was just changed: new records can take a little while to take effect. Check with
dig +short example.co.nzthat it returns your VPS IP before requesting a certificate.
Setting up WordPress? Our guide to installing WordPress on a LEMP stack includes the Certbot step.
Need help?
Our Cloud VPS plans are self-managed, so you're responsible for installing, securing and maintaining the software on your server. If something on our side isn't working, such as the network, or your VPS won't boot, open a support ticket. New to your VPS? Start with our Cloud VPS Getting Started Guide.







