Ravindra BagaleCourses & study guides

13. Multiple Websites on One Server and HTTPS with Certbot

13.4 HTTPS with Certbot (Let's Encrypt)

Browser plain HTTP la "Not secure" dakhavto. Let's Encrypt free certificates deto aani certbot te install karto, config badalto aani renew pan karto. Domain tumchya Elastic IP la point hava aani ports 80 va 443 ughde have.

# Ubuntu
sudo apt install -y certbot python3-certbot-nginx      # or python3-certbot-apache
sudo certbot --nginx -d mysite.example.com             # or --apache

# Amazon Linux 2023
sudo yum install -y certbot python3-certbot-nginx      # or python3-certbot-apache
sudo certbot --nginx -d mysite.example.com

# CentOS Stream 9 (certbot comes from EPEL)
sudo yum install -y epel-release
sudo yum install -y certbot python3-certbot-nginx
sudo certbot --nginx -d mysite.example.com

Amazon Linux 2023: if the certbot package is not found

Install certbot in a Python virtual environment instead: sudo python3 -m venv /opt/certbot && sudo /opt/certbot/bin/pip install certbot certbot-nginx && sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot (use certbot-apache for Apache).

Certbot edits the server block, installs the certificate and sets up automatic renewal (check with sudo certbot renew --dry-run).

sudo certbot --nginx -d example.com -d www.example.com -d blog.example.com     # or --apache
sudo certbot certificates                 # list certificates and expiry dates
sudo certbot renew --dry-run              # test automatic renewal

Certbot verifies that you control each name by making an HTTP request to it, so every -d name must already resolve to this server. If one name fails, check dig name +short first. Wildcard certificates (*.example.com) need a DNS challenge (a TXT record) instead. Use them later, once you're comfortable.

sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com --redirect   # also adds HTTP→HTTPS
curl -I http://yourdomain.com          # expect 301 to https://
curl -I https://yourdomain.com         # expect 200

Why this matters for security

Without HTTPS, anyone on the same Wi-Fi can read logins and steal session cookies. With HTTPS, add the redirect so no page is served over HTTP, and set cookies with the Secure flag. Let's Encrypt certificates are short-lived, so automatic renewal must be tested.

Ravindra Bagale's Tip

Certbot "Timeout during connect" deto tevha khup students certbot punha punha chalavtat – aani Let's Encrypt che rate limits lagtat. Aadhi dig yourdomain.com +short ne DNS tumchya EIP la aahe ka aani security group madhe 80 open aahe ka te bagha, mag ekdach chalva. Test sathi --dry-run aahe.

Lab

Get a certificate for your domain and www with --redirect. Run sudo certbot renew --dry-run and sudo certbot certificates and note the expiry date.