# 7.13 HTTPS जोडूया: domain वापरणारा lab

Source: https://ravindrabagale.com/mr/aws/ch07-static-website-hosting-3-oses-2-web-servers/7-13-adding-https-optional-needs-a-domain.html
Language: mr (Marathi with English technical terms)

या lesson मध्ये domain-based Certbot workflow वापरतो. Domain चा A record तुमच्या स्थिर public IP कडे आणि योग्य server_name/ServerName तयार असावा.

मूळ माहितीतील update: “Bare IP साठी Let’s Encrypt certificate मिळत नाही” हे आता चुकीचं आहे. 2026 पासून IPv4/IPv6 साठी short-lived IP certificates उपलब्ध आहेत. त्यांचा वेगळा workflow/renewal आवश्यक आहे. इथे domain lab चाच अभ्यास करू. Let’s Encrypt ची अधिकृत माहिती.

HTTPS वापरण्यासाठी 443 open हवा; या HTTP-01 validation पद्धतीसाठी port 80 देखील public reachability सह लागतो. DNS A/AAAA records योग्य server वर resolve झाले पाहिजेत.

# Ubuntu
sudo apt install -y certbot python3-certbot-nginx      # or python3-certbot-apache
sudo certbot --nginx -d mysite.example.com             # or --apache

# Amazon Linux 2023
sudo yum install -y certbot python3-certbot-nginx      # or python3-certbot-apache
sudo certbot --nginx -d mysite.example.com

# CentOS Stream 9 (certbot comes from EPEL)
sudo yum install -y epel-release
sudo yum install -y certbot python3-certbot-nginx
sudo certbot --nginx -d mysite.example.com

OS/package version नुसार availability बदलते. Current supported installation साठी Certbot instructions पाहा. Apache साठी योग्य plugin/--apache निवडा.

AL2023 package मिळत नसेल तर

Source चा venv पर्याय: sudo python3 -m venv /opt/certbot && sudo /opt/certbot/bin/pip install certbot certbot-nginx && sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot. आधीचा binary/package conflict आणि supported Python requirements तपासा. Apache साठी certbot-apache.

Certificate install झाल्यावर HTTPS request test करा. sudo certbot renew --dry-run renewal test आहे; scheduler असल्याचा पुरावा नाही. OS package timer/cron आहे का तपासा. Pip/venv install मध्ये official instructions नुसार renewal scheduler वेगळा configure करावा लागू शकतो.

Lab

Domain असेल तर certificate आणि dry-run करा; automatic timer/cron verify करा. Domain नसेल तर HTTP status पाहा आणि या domain workflow ची checklist लिहा: DNS, HTTP-01 साठी 80, HTTPS साठी 443 आणि renewal.

रवींद्र बागले यांची tip

Certbot आधी dig +short domain करा. A आणि AAAA पैकी चुकीचा record राहिला तर validation fail होऊ शकते. 443 उघडणं एकटं HTTP-01 साठी पुरेसं नाही.
