Skip to content
Shellbay

Web & TLS · about 3 min · 6 steps

HTTPS certificate with Certbot

Gets a free Let's Encrypt certificate for your domain, turns on HTTPS in Nginx and renews it automatically.

Runs on

  • Debian / Ubuntu: supported
  • RHEL / Fedora: supported — Uses EPEL on RHEL-compatible systems.
  • Alpine: supported

Before you start

  • Run the Nginx web server workflow first.

What it changes on your server

  • Installs Certbot and its Nginx plugin.
  • Adds a site for your domain if Nginx doesn't have one yet.
  • Creates a Let's Encrypt account with your email and gets a certificate.
  • Redirects HTTP to HTTPS and renews the certificate before it expires.

What Shellbay asks you

  1. Which domain is the certificate for?

    Let's Encrypt checks that the domain points to this server, so its DNS record must already be set. Enter the exact name visitors type, without https://.

    Domain
    A domain name, such as example.com

    Example: www.example.com

    Shellbay checks the domain already points at this server.

  2. Your Let's Encrypt account

    Let's Encrypt emails you if a certificate is about to expire without renewing. Using it requires agreeing to their Subscriber Agreement at letsencrypt.org/repository.

    Email for expiry notices
    An email address
    I agree to the Let's Encrypt Subscriber Agreement
    Your agreement

    Example: you@example.com

Steps

  1. Confirm the agreement
  2. Prepare packages
  3. Install Certbot
  4. Make sure Nginx has a site for the domain
  5. Get the certificate and turn on HTTPS
  6. Renew automatically

Shellbay checks the server before the first step, and stops at the first step that fails.

When it's done

  • https://‹domain› now has a Let's Encrypt certificate, and HTTP redirects to HTTPS.
  • Renewal runs automatically. Make sure ports 80 and 443 stay open in your firewall.