How to Install a Free SSL Certificate on EC2 (Let's Encrypt + Certbot)
To install a free SSL certificate on AWS EC2, point your domain's A record to the instance's Elastic IP, open ports 80 and 443 in the security group, install Certbot (sudo yum install -y certbot python3-certbot-nginx on Amazon Linux 2023) and run sudo certbot --nginx -d example.com -d www.example.com --redirect. Certbot gets a Let's Encrypt certificate, configures Nginx for HTTPS and sets up renewal. Let's Encrypt does not issue certificates for a bare IP address, so you need a domain.
Friends, the domain is set up and the website works – but the browser says "Not secure". And if you want to send her the link, you need a proper domain and a 🔒! In this guide we install a free Let's Encrypt certificate with Certbot. One command, but three things must be ready before it – the domain, ports 80/443 and server_name. Every site with a login or contact form needs HTTPS, because visitors type a password or mobile number there.
मित्रांनो, डोमेन लावलं, वेबसाइट चालू आहे – पण ब्राउझर "Not secure" दाखवतो. आणि तिला लिंक पाठवायची तर प्रॉपर डोमेन आणि 🔒 हवाच! या गाइड मध्ये Let's Encrypt चं फ्री सर्टिफिकेट Certbot ने लावूया. एकच कमांड, पण त्याच्या आधी तीन तयारी – डोमेन, पोर्ट 80/443 आणि server_name. लॉगिन किंवा कॉन्टॅक्ट फॉर्म असलेली प्रत्येक साइट HTTPS वरच हवी, कारण व्हिजिटर्स तिथे पासवर्ड किंवा मोबाईल नंबर टाकत असतात.
दोस्तों, डोमेन लग गया, वेबसाइट चल रही है – पर ब्राउज़र "Not secure" दिखाता है. और उसे लिंक भेजनी है तो प्रॉपर डोमेन और 🔒 चाहिए ही! इस गाइड में Let's Encrypt का फ़्री सर्टिफ़िकेट Certbot से लगाएँगे. एक ही कमांड, पर उससे पहले तीन तैयारी – डोमेन, पोर्ट 80/443 और server_name. लॉगिन या कॉन्टैक्ट फ़ॉर्म वाली हर साइट HTTPS पर ही होनी चाहिए, क्योंकि विज़िटर्स वहाँ पासवर्ड या मोबाइल नंबर डालते हैं.
Quick answer
On Amazon Linux 2023 with Nginx, once example.com points to your Elastic IP and ports 80/443 are open:
sudo yum install -y certbot python3-certbot-nginx
sudo certbot --nginx -d example.com -d www.example.com --redirect
curl -I https://example.com # expect HTTP/1.1 200 OK
sudo certbot renew --dry-run # test automatic renewal
For Apache: sudo yum install -y python3-certbot-apache mod_ssl and sudo certbot --apache -d example.com -d www.example.com.
What do I need before installing an SSL certificate?
- A domain whose A record points to your Elastic IP — see How to Connect a GoDaddy Domain to AWS EC2. Check:
dig example.com +shortshows your Elastic IP. - Ports 80 and 443 open to
0.0.0.0/0— see How to Open Port 80 and 443 in an EC2 Security Group. Let's Encrypt checks your domain over port 80. - A web server that already answers for the domain:
server_name example.com www.example.com;in Nginx (see How to Host a Static Website on EC2 with Nginx), orServerName/ServerAliasin Apache.curl -I http://example.comreturns 200.
How does HTTPS work?
The browser says hello on port 443, the server sends its Let's Encrypt certificate, the browser checks it and shows the padlock. After that, all data travels encrypted.
ब्राउझर पोर्ट 443 वर hello म्हणतो, सर्व्हर त्याचं Let's Encrypt सर्टिफिकेट पाठवतो, ब्राउझर ते चेक करतो आणि पॅडलॉक दाखवतो. त्यानंतर सगळा डेटा encrypted जातो.
ब्राउज़र पोर्ट 443 पर hello बोलता है, सर्वर अपना Let's Encrypt सर्टिफ़िकेट भेजता है, ब्राउज़र उसे चेक करता है और पैडलॉक दिखाता है. उसके बाद सारा डेटा encrypted जाता है.
HTTPS is HTTP inside TLS encryption. The server proves its identity with a certificate signed by a trusted certificate authority — here Let's Encrypt, which is free. Certbot is the tool that asks Let's Encrypt for the certificate, proves that you control the domain, installs the certificate into Nginx or Apache and renews it before it expires.
How do I install a free Let's Encrypt certificate with Certbot?
Step 1 — Check DNS and the web server first
dig example.com +short # must print your Elastic IP
dig www.example.com +short # must end with your Elastic IP
curl -I http://example.com # must return 200 from your server
Certbot verifies each name with an HTTP request, so every -d name must already resolve to this server.
Step 2 — Install Certbot
# Amazon Linux 2023 + Nginx
sudo yum install -y certbot python3-certbot-nginx
# Amazon Linux 2023 + Apache (the Apache plugin needs mod_ssl)
sudo yum install -y certbot python3-certbot-apache mod_ssl
If the certbot package is not found on your Amazon Linux 2023 image, install it in a Python virtual environment instead:
sudo python3 -m venv /opt/certbot
sudo /opt/certbot/bin/pip install certbot certbot-nginx # certbot-apache for Apache
sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot
On Ubuntu: sudo apt install -y certbot python3-certbot-nginx. On CentOS Stream 9, Certbot comes from EPEL (sudo yum install -y epel-release first).
Step 3 — Get the certificate and turn on HTTPS
sudo certbot --nginx -d example.com -d www.example.com --redirect
Certbot asks for an email address (for expiry warnings) and for agreement to the terms, then edits your server block: it adds listen 443 ssl, the certificate paths under /etc/letsencrypt/live/example.com/, and with --redirect a 301 from HTTP to HTTPS. For Apache use sudo certbot --apache -d example.com -d www.example.com.
Step 4 — Test HTTPS
curl -I http://example.com # expect 301 Moved Permanently → https://
curl -I https://example.com # expect HTTP/1.1 200 OK
sudo certbot certificates # names, paths and expiry date
Open https://example.com in the browser: the padlock is there. Send the link!
Ravindra Bagale's Tip
Many students run certbot before the domain's A record points to the Elastic IP or before port 80 is open; validation fails, they try again and again – and hit Let's Encrypt's rate limits. First dig +short, then the security group, then certbot once. If you just want to test, there is --dry-run.
Ravindra Bagale's Tip – मराठी
खूप स्टुडंट्स डोमेनचा A रेकॉर्ड Elastic IP कडे पॉइंट होण्याआधी किंवा पोर्ट 80 ओपन करण्याआधी certbot चालवतात, validation फेल होतं, आणि मग पुन्हा पुन्हा ट्राय करतात – आणि Let's Encrypt चे rate limits लागतात. आधी dig +short, मग security group, मग एकदाच certbot. टेस्ट करायचं असेल तर --dry-run आहे.
Ravindra Bagale's Tip – हिंदी
बहुत स्टूडेंट्स डोमेन का A रिकॉर्ड Elastic IP पर पॉइंट होने से पहले या पोर्ट 80 ओपन करने से पहले certbot चला देते हैं, validation फेल होता है, और फिर बार-बार ट्राय करते हैं – और Let's Encrypt के rate limits लग जाते हैं. पहले dig +short, फिर security group, फिर एक बार certbot. टेस्ट करना हो तो --dry-run है.
How do I make sure the certificate renews automatically?
Let's Encrypt certificates are short-lived, so renewal must work without you. Test it:
sudo certbot renew --dry-run # must end with "Congratulations, all simulated renewals succeeded"
systemctl list-unit-files | grep -i certbot # is a certbot renewal timer installed?
- If the list shows
certbot-renew.timer, make sure it is enabled:sudo systemctl enable --now certbot-renew.timer. - If nothing is listed (for example after the virtual-environment install), add the renewal job from the official Certbot instructions. Amazon Linux 2023 has no cron daemon by default, so install it first:
sudo yum install -y cronie && sudo systemctl enable --now crond
echo "0 0,12 * * * root /opt/certbot/bin/python -c 'import random; import time; time.sleep(random.random() * 3600)' && sudo certbot renew -q" | sudo tee -a /etc/crontab > /dev/null
Ravindra Bagale's Tip
💡 Don't think the job is over once the certificate is installed. Run sudo certbot renew --dry-run today and write the expiry date from sudo certbot certificates in your calendar. If renewal fails, one day your visitors will suddenly see a scary "Not secure" warning. Stay alert!
Ravindra Bagale's Tip – मराठी
💡 सर्टिफिकेट लावलं की काम संपलं असं समजू नका. आजच sudo certbot renew --dry-run चालवा आणि sudo certbot certificates मधली expiry डेट कॅलेंडर मध्ये लिहा. Renewal फेल झालं तर एक दिवस अचानक तुमच्या व्हिजिटर्स ना भीतीदायक "Not secure" वॉर्निंग दिसेल. लक्ष ठेवा!
Ravindra Bagale's Tip – हिंदी
💡 सर्टिफ़िकेट लग गया तो काम खत्म, ऐसा मत समझो. आज ही sudo certbot renew --dry-run चलाओ और sudo certbot certificates वाली expiry डेट कैलेंडर में लिख लो. Renewal फेल हुआ तो एक दिन अचानक आपके विज़िटर्स को डरावनी "Not secure" वॉर्निंग दिखेगी. ध्यान रखो!
How do I fix common Certbot errors?
Ghabru naka 😅 — the message tells you where to look:
| Symptom | Likely cause | Fix |
|---|---|---|
| Timeout during connect (likely firewall problem) | Port 80 closed, or DNS points elsewhere | Allow HTTP 80; dig example.com +short must show your EIP |
| DNS problem: NXDOMAIN looking up A for ... | The name has no A record yet | Add the record (e.g. CNAME www), wait for TTL, retry |
| Could not automatically find a matching server block | No server_name example.com in Nginx |
Add both names to server_name, sudo nginx -t, reload |
| too many failed authorizations recently | Rate limit after repeated failures | Fix DNS/port first; test with --dry-run; wait before retrying |
https:// refuses to connect |
Port 443 closed in the security group | Allow HTTPS 443 from 0.0.0.0/0 |
| Browser warns about the certificate | Visiting a name not on the certificate, or the bare IP | Use a name you passed with -d; add it with --expand |
| Apache: plugin fails to load SSL | mod_ssl not installed |
sudo yum install -y mod_ssl, sudo service httpd restart |
Learn it properly
This guide is the short path. The free AWS course explains every step in depth, with labs:
Got it? First DNS, then ports 80/443, then server_name, and finally a single certbot command – that's the order. Don't forget the renewal --dry-run. Your site is secure now – send the link with confidence.
समजलं का? आधी DNS, मग पोर्ट 80/443, मग server_name, आणि शेवटी एकच certbot कमांड – हाच क्रम. Renewal चा --dry-run विसरू नका. आता तुमची साइट सिक्युअर आहे – लिंक बिनधास्त पाठवा.
समझ आया? पहले DNS, फिर पोर्ट 80/443, फिर server_name, और आख़िर में एक ही certbot कमांड – यही क्रम है. Renewal का --dry-run मत भूलना. अब आपकी साइट सिक्योर है – लिंक बेफ़िक्र होकर भेजो.
Frequently asked questions
How do I install a free SSL certificate on EC2?
Point your domain to the Elastic IP, open ports 80 and 443, install Certbot (sudo yum install -y certbot python3-certbot-nginx on Amazon Linux 2023) and run sudo certbot --nginx -d example.com -d www.example.com.
Can I get a Let's Encrypt certificate for an EC2 public IP?
No. Let's Encrypt issues certificates for domain names, not for a bare IP. You need a domain whose A record points to your Elastic IP.
Why does Certbot fail with "Timeout during connect"?
Let's Encrypt could not reach your server on port 80 for the domain. Check dig example.com +short (it must show your Elastic IP) and allow HTTP 80 in the security group, then run certbot once more.
Does the certificate renew automatically?
Certbot sets up renewal. Test it with sudo certbot renew --dry-run and list expiry dates with sudo certbot certificates. Certificates are short-lived, so renewal must work.
How do I redirect HTTP to HTTPS?
Add --redirect to the certbot command, or choose the redirect option when certbot asks. Then curl -I http://example.com returns a 301 to https://.
How do I use Certbot with Apache instead of Nginx?
Install python3-certbot-apache and mod_ssl, and run sudo certbot --apache -d example.com -d www.example.com. Everything else is the same.