October 08, 2026 · by Alex M.
If you manage a SSD VPS or an NVMe VPS and want to secure your site's traffic, the first essential step is enabling HTTPS with a valid SSL certificate. Let's Encrypt provides free SSL/TLS certificates recognized by all modern browsers, and Certbot is the official client that fully automates obtaining and renewing them.
In this guide you'll learn how to install Certbot on Ubuntu 22.04, obtain certificates for domains on both Nginx and Apache, configure automatic renewal, and avoid the most common pitfalls.
Modern browsers flag any HTTP site as "Not Secure". Search engines, especially Google, penalize pages without HTTPS in their rankings. Beyond security (encrypting data between client and server), a valid SSL certificate:
If you need commercial SSL certificates with extended validation (EV/OV), you can purchase them directly from CLIQHOST — SSL Certificates. But for the vast majority of websites, Let's Encrypt is more than sufficient.
Before starting, make sure you have:
example.com) DNS configured to point to your VPS IPVerify the web server is running:
systemctl status nginx
# or
systemctl status apache2
Before any installation, update the package list:
sudo apt update && sudo apt upgrade -y
Install Certbot and the appropriate plugin for your web server:
sudo apt install certbot python3-certbot-nginx -y
sudo apt install certbot python3-certbot-apache -y
Alternatively, use Snap (recommended by the Certbot team for the latest version):
sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbot
For Nginx:
sudo certbot --nginx -d example.com -d www.example.com
For Apache:
sudo certbot --apache -d example.com -d www.example.com
Certbot will:
During the process you'll be asked for:
If your web server isn't configured yet or you want to obtain the certificate independently:
sudo certbot certonly --standalone -d example.com -d www.example.com
Certificates will be saved to:
/etc/letsencrypt/live/example.com/
├── cert.pem # the certificate itself
├── chain.pem # the certification chain
├── fullchain.pem # cert + chain (used by Nginx/Apache)
└── privkey.pem # the private key
Once Certbot finishes, verify the Nginx configuration:
sudo nginx -t
sudo systemctl reload nginx
Or for Apache:
sudo apache2ctl configtest
sudo systemctl reload apache2
Visit your site in a browser at https://example.com and check for the padlock icon. You can also run:
curl -I https://example.com
You should see HTTP/2 200 or HTTP/1.1 200 OK in the response.
If you prefer full control over the configuration, here's a complete Nginx virtual host example with SSL:
server {
listen 80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name example.com www.example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/example.com/chain.pem;
# Recommended security parameters
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;
ssl_prefer_server_ciphers off;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 1d;
ssl_stapling on;
ssl_stapling_verify on;
add_header Strict-Transport-Security "max-age=63072000" always;
root /var/www/example.com;
index index.html index.php;
location / {
try_files $uri $uri/ =404;
}
}
This configuration enables TLS 1.2/1.3, OCSP Stapling and HSTS — a solid security baseline for any Linux server.
Let's Encrypt certificates are valid for 90 days. Certbot automatically installs a systemd timer (or cron job) that renews certificates 30 days before expiry.
Check the timer:
sudo systemctl status certbot.timer
Test renewal without making real changes:
sudo certbot renew --dry-run
If everything works, you'll see:
Congratulations, all simulated renewals succeeded:
/etc/letsencrypt/live/example.com/fullchain.pem (success)
After renewal, the web server must be reloaded to load the new certificate. Create a hook script:
sudo nano /etc/letsencrypt/renewal-hooks/post/reload-nginx.sh
Content:
#!/bin/bash
systemctl reload nginx
Make it executable:
sudo chmod +x /etc/letsencrypt/renewal-hooks/post/reload-nginx.sh
sudo certbot --nginx -d example.com -d www.example.com -d blog.example.com -d shop.example.com
Wildcard certificates require DNS validation (not HTTP). Use the dns-01 challenge:
sudo certbot certonly --manual --preferred-challenges dns -d "*.example.com" -d example.com
Certbot will ask you to add a TXT record in your DNS zone:
_acme-challenge.example.com. 300 IN TXT "value_generated_by_certbot"
Add the record in your registrar's DNS panel, wait for propagation (1–5 minutes), then press Enter to continue.
Note: If you use server management services from CLIQHOST, our team can set up this automation using DNS-specific plugins (e.g. certbot-dns-cloudflare).
Let's Encrypt limits to 5 certificates per domain per 7 days. If you hit the limit, use the --staging flag for testing:
sudo certbot --nginx --staging -d example.com
Check your firewall:
sudo ufw status
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
Make sure the domain configuration file exists in /etc/nginx/sites-enabled/. Certbot searches for the server_name directive to identify the correct virtual host.
Check the logs:
sudo journalctl -u certbot.timer
cat /var/log/letsencrypt/letsencrypt.log
After configuration, test your SSL rating with SSL Labs — a free analysis tool that checks protocols, ciphers and the certificate chain. A correct configuration should achieve a grade of A or A+.
You can also verify locally:
openssl s_client -connect example.com:443 -tls1_3
For high-traffic servers, consider a managed dedicated server where SSL configuration is handled professionally. Entry-level projects can start with a cost-effective VPS-1C plan and upgrade as traffic grows.
Want to read more about server security and VPS configuration? Explore the CLIQHOST blog for more practical guides.
Certbot with Let's Encrypt is the industry standard for free SSL certificates on any Linux VPS. Installation takes under 10 minutes, renewal is fully automatic, and the security provided matches commercial certificates for typical websites.
If you're starting from scratch and looking for a high-performance SSD VPS in Moldova to build your web infrastructure on, CLIQHOST offers flexible plans with full root access — perfect for all the configurations described in this guide.
Have questions or need help with SSL setup? Contact the CLIQHOST team — we're here to help.
Real reviews from customers who trust CLIQHOST for performance, reliability and expert technical support.
"We moved our online shop from a foreign host and the difference is night and day — pages load instantly and support replies in minutes, in Romanian."
"Migrated 12 client sites to CLIQHOST. Free migration, zero downtime, and the cPanel setup is exactly what my team needed. Highly recommend."
"Our NVMe VPS handles traffic spikes without a sweat. Full root, local datacenter, and billing in MDL — everything we wanted from a provider."