// SSD VPS

How to Install and Configure Certbot (Let's Encrypt) on a Linux VPS: Complete Guide — CLIQHOST

October 08, 2026 · by Alex M.

How to Install and Configure Certbot (Let's Encrypt) on a Linux VPS: Complete Guide — CLIQHOST

If you manage a SSD VPS or an NVMe VPS and want to secure your site's traffic, the first essential step is enabling HTTPS with a valid SSL certificate. Let's Encrypt provides free SSL/TLS certificates recognized by all modern browsers, and Certbot is the official client that fully automates obtaining and renewing them.

In this guide you'll learn how to install Certbot on Ubuntu 22.04, obtain certificates for domains on both Nginx and Apache, configure automatic renewal, and avoid the most common pitfalls.


Why SSL is Mandatory in 2025

Modern browsers flag any HTTP site as "Not Secure". Search engines, especially Google, penalize pages without HTTPS in their rankings. Beyond security (encrypting data between client and server), a valid SSL certificate:

  • Builds user trust
  • Is a prerequisite for HTTP/2
  • Is required for e-commerce and login forms
  • Eliminates browser security warnings

If you need commercial SSL certificates with extended validation (EV/OV), you can purchase them directly from CLIQHOST — SSL Certificates. But for the vast majority of websites, Let's Encrypt is more than sufficient.


Prerequisites

Before starting, make sure you have:

  1. SSH access to your server (a Linux VPS running Ubuntu 22.04 or Debian 12)
  2. Your domain (e.g. example.com) DNS configured to point to your VPS IP
  3. Nginx or Apache installed on the server
  4. Ports 80 and 443 open in the firewall

Verify the web server is running:

systemctl status nginx
# or
systemctl status apache2

Step 1: Update the System and Install Certbot

Before any installation, update the package list:

sudo apt update && sudo apt upgrade -y

Install Certbot and the appropriate plugin for your web server:

For Nginx:

sudo apt install certbot python3-certbot-nginx -y

For Apache:

sudo apt install certbot python3-certbot-apache -y

Alternatively, use Snap (recommended by the Certbot team for the latest version):

sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbot

Step 2: Obtain an SSL Certificate for Your Domain

For Nginx:

sudo certbot --nginx -d example.com -d www.example.com

For Apache:

sudo certbot --apache -d example.com -d www.example.com

Certbot will:

  1. Verify that your domain points to this server
  2. Generate the SSL certificate
  3. Automatically modify the Nginx/Apache configuration for HTTPS
  4. Enable HTTP → HTTPS redirect (optional but recommended)

During the process you'll be asked for:

  • Your email address (for expiry notifications)
  • Acceptance of the terms of service
  • Whether you want automatic HTTP-to-HTTPS redirect

Standalone method (without an active web server)

If your web server isn't configured yet or you want to obtain the certificate independently:

sudo certbot certonly --standalone -d example.com -d www.example.com

Certificates will be saved to:

/etc/letsencrypt/live/example.com/
├── cert.pem        # the certificate itself
├── chain.pem       # the certification chain
├── fullchain.pem   # cert + chain (used by Nginx/Apache)
└── privkey.pem     # the private key

Step 3: Verify the Generated SSL Configuration

Once Certbot finishes, verify the Nginx configuration:

sudo nginx -t
sudo systemctl reload nginx

Or for Apache:

sudo apache2ctl configtest
sudo systemctl reload apache2

Visit your site in a browser at https://example.com and check for the padlock icon. You can also run:

curl -I https://example.com

You should see HTTP/2 200 or HTTP/1.1 200 OK in the response.


Step 4: Manual Nginx SSL Configuration (Advanced)

If you prefer full control over the configuration, here's a complete Nginx virtual host example with SSL:

server {
    listen 80;
    server_name example.com www.example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl http2;
    server_name example.com www.example.com;

    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    ssl_trusted_certificate /etc/letsencrypt/live/example.com/chain.pem;

    # Recommended security parameters
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;
    ssl_prefer_server_ciphers off;

    ssl_session_cache shared:SSL:10m;
    ssl_session_timeout 1d;
    ssl_stapling on;
    ssl_stapling_verify on;

    add_header Strict-Transport-Security "max-age=63072000" always;

    root /var/www/example.com;
    index index.html index.php;

    location / {
        try_files $uri $uri/ =404;
    }
}

This configuration enables TLS 1.2/1.3, OCSP Stapling and HSTS — a solid security baseline for any Linux server.


Step 5: Configure Automatic Renewal

Let's Encrypt certificates are valid for 90 days. Certbot automatically installs a systemd timer (or cron job) that renews certificates 30 days before expiry.

Check the timer:

sudo systemctl status certbot.timer

Test renewal without making real changes:

sudo certbot renew --dry-run

If everything works, you'll see:

Congratulations, all simulated renewals succeeded:
  /etc/letsencrypt/live/example.com/fullchain.pem (success)

Add a post-renewal hook

After renewal, the web server must be reloaded to load the new certificate. Create a hook script:

sudo nano /etc/letsencrypt/renewal-hooks/post/reload-nginx.sh

Content:

#!/bin/bash
systemctl reload nginx

Make it executable:

sudo chmod +x /etc/letsencrypt/renewal-hooks/post/reload-nginx.sh

Step 6: Certificates for Multiple Domains and Wildcard

Multi-domain certificates (SAN):

sudo certbot --nginx -d example.com -d www.example.com -d blog.example.com -d shop.example.com

Wildcard certificates (*.example.com):

Wildcard certificates require DNS validation (not HTTP). Use the dns-01 challenge:

sudo certbot certonly --manual --preferred-challenges dns -d "*.example.com" -d example.com

Certbot will ask you to add a TXT record in your DNS zone:

_acme-challenge.example.com. 300 IN TXT "value_generated_by_certbot"

Add the record in your registrar's DNS panel, wait for propagation (1–5 minutes), then press Enter to continue.

Note: If you use server management services from CLIQHOST, our team can set up this automation using DNS-specific plugins (e.g. certbot-dns-cloudflare).


Troubleshooting: Common Issues

Error: "Too many certificates already issued"

Let's Encrypt limits to 5 certificates per domain per 7 days. If you hit the limit, use the --staging flag for testing:

sudo certbot --nginx --staging -d example.com

HTTP validation error (port 80 blocked)

Check your firewall:

sudo ufw status
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

Certbot doesn't find the Nginx configuration

Make sure the domain configuration file exists in /etc/nginx/sites-enabled/. Certbot searches for the server_name directive to identify the correct virtual host.

Certificate doesn't auto-renew

Check the logs:

sudo journalctl -u certbot.timer
cat /var/log/letsencrypt/letsencrypt.log

Checking SSL Security with External Tools

After configuration, test your SSL rating with SSL Labs — a free analysis tool that checks protocols, ciphers and the certificate chain. A correct configuration should achieve a grade of A or A+.

You can also verify locally:

openssl s_client -connect example.com:443 -tls1_3

SSL Security Best Practices

  1. Enable HSTS — force browsers to always use HTTPS
  2. Disable TLS 1.0 and 1.1 — vulnerable protocols, accept only TLS 1.2+
  3. Enable OCSP Stapling — reduces SSL handshake latency
  4. Use RSA 2048+ or ECDSA keys — Certbot generates ECDSA by default
  5. Monitor expiry — Certbot sends email 30 days before expiry

For high-traffic servers, consider a managed dedicated server where SSL configuration is handled professionally. Entry-level projects can start with a cost-effective VPS-1C plan and upgrade as traffic grows.

Want to read more about server security and VPS configuration? Explore the CLIQHOST blog for more practical guides.


Conclusion

Certbot with Let's Encrypt is the industry standard for free SSL certificates on any Linux VPS. Installation takes under 10 minutes, renewal is fully automatic, and the security provided matches commercial certificates for typical websites.

If you're starting from scratch and looking for a high-performance SSD VPS in Moldova to build your web infrastructure on, CLIQHOST offers flexible plans with full root access — perfect for all the configurations described in this guide.

Have questions or need help with SSL setup? Contact the CLIQHOST team — we're here to help.

SHARE
// what clients say

What Our Clients Say

Real reviews from customers who trust CLIQHOST for performance, reliability and expert technical support.

★★★★★

"We moved our online shop from a foreign host and the difference is night and day — pages load instantly and support replies in minutes, in Romanian."

AM
Andrei M.
eCommerce owner · Chișinău
★★★★★

"Migrated 12 client sites to CLIQHOST. Free migration, zero downtime, and the cPanel setup is exactly what my team needed. Highly recommend."

EV
Elena V.
Web agency · Bălți
★★★★★

"Our NVMe VPS handles traffic spikes without a sweat. Full root, local datacenter, and billing in MDL — everything we wanted from a provider."

DC
Dmitri C.
SaaS founder · Chișinău