SSL Free Certificate Application - Certbot
We know that using SSL (Secure Sockets Layer) certificates is very important for websites and online services. SSL certificates protect data from being eavesdropped on or tampered with by encrypting the communication between users and servers.
In this chapter, we will introduce how to use the Certbot tool to apply for free SSL certificates.
What is Certbot?
Certbot is an open-source automation tool used to obtain and renew free SSL/TLS certificates provided by Let's Encrypt.
Let's Encrypt is a certificate authority (CA) operated by the Internet Security Research Group (ISRG). It provides an automated process for generating and renewing certificates, allowing website administrators to easily enable HTTPS encryption for their sites.
The main features of Certbot include:
- Automation: It can automatically verify domain ownership and apply for certificates.
- Free: It uses the free certificates provided by Let's Encrypt.
- Compatibility: Supports multiple web servers, such as Apache, Nginx, etc.
- Ease of use: Provides a command-line interface, making installation and use simple.
- Renewal: Automatically handles certificate renewal, ensuring the website's HTTPS connection remains valid at all times.
Certificates issued by Let's Encrypt are valid for 90 days. Certbot automatically configures certificate renewal tasks to ensure certificates do not expire.
Certbot Installation
1. Install Certbot on Ubuntu/Debian systems
Install using APT:
sudo apt update sudo apt install certbot
After the installation is complete, Certbot is ready to use.
Install the Snap version:
Snap is the official recommended installation method for Certbot, especially for long-term support Ubuntu versions.
sudo snap install core sudo snap refresh core sudo snap install --classic certbot sudo ln -s /snap/bin/certbot /usr/bin/certbot # 这一步是为了确保 certbot 命令能全局使用
2. Install Certbot on CentOS/RHEL systems
Install the EPEL repository (for CentOS 7 and below):
sudo yum install epel-release
sudo yum install certbot
3. Install Certbot on macOS
On macOS, you can install Certbot using Homebrew:
brew install certbot
For more content, you can visit the Certbot websitehttps://certbot.eff.org/View the installation methods for each system platform:

After installation, use the following command to check the installed version of certbot:
certbot --version
Certificate Application and Renewal
After installing certbot, you can use the following command to apply for a certificate. Note that *.example.com should be replaced with your own domain:
certbot certonly -d *.example.com --manual --preferred-challenges dns --server https://acme-v02.api.letsencrypt.org/directory
After executing the above command, fill in the information:
Saving debug log to /var/log/letsencrypt/letsencrypt.log Enter email address (used for urgent renewal and security notices) (Enter 'c' to cancel): xxx@qq.com. # 这里输入你的邮箱 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Please read the Terms of Service at https://letsencrypt.org/documents/LE-SA-v1.4-April-3-2024.pdf. You must agree in order to register with the ACME server. Do you agree? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: Y # 输入 Y - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Would you be willing, once your first certificate is successfully issued, to share your email address with the Electronic Frontier Foundation, a founding partner of the Let's Encrypt project and the non-profit organization that develops Certbot? We'd like to send you email about our work encrypting the web, EFF news, campaigns, and ways to support digital freedom. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: Y # 输入 Y Account registered. Requesting a certificate for *.example.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Please deploy a DNS TXT record under the name: xxxxxxx.example.com. # 这里需要设置域名解析,需要到域名后台填写信息,参考下图 with the following value: aIwqY00CZtziVwr-xxxxxxxxxxxxxx # 这里是域名解析的内容,参考下图 Before continuing, verify the TXT record has been deployed. Depending on the DNS provider, this may take some time, from a few seconds to multiple minutes. You can check if it has finished deploying with aid of online tools, such as the Google Admin Toolbox: https://toolbox.googleapps.com/apps/dig/#TXT/_acme-challenge.example.com. Look for one or more bolded line(s) below the line ';ANSWER'. It should show the value(s) you've just added. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Press Enter to Continue # 参考下图设置完域名解析后,按回车就可以生成了,记住一定要先解析设置完成后再回车,然后生成的证书信息如下: Successfully received certificate. Certificate is saved at: /etc/letsencrypt/live/example.com/fullchain.pem Key is saved at: /etc/letsencrypt/live/example.com/privkey.pem This certificate expires on 2024-12-21. These files will be updated when the certificate renews. NEXT STEPS: - This certificate will not be renewed automatically. Autorenewal of --manual certificates requires the use of an authentication hook script (--manual-auth-hook) but one was not provided. To renew this certificate, repeat this same certbot command before the certificate's expiry date. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - If you like Certbot, please consider supporting our work by: * Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate * Donating to EFF: https://eff.org/donate-le - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Set up domain resolution to verify the certificate:

The certificates issued by Let's Encrypt are valid for 90 days. You can use the following command to renew the certificate:
certbot certonly --force-renewal --manual -d '*.example.com' \ --preferred-challenges dns \ --server https://acme-v02.api.letsencrypt.org/directory
After executing the above renewal command, it will prompt us to update the DNS resolution records:
Saving debug log to /var/log/letsencrypt/letsencrypt.log Requesting a certificate for *.jysahre.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Please deploy a DNS TXT record under the name: _acme-challenge.jysahre.com. with the following value: ckxo1wGXbP1CtNQ3ZRfvHxxxxxx # 这里会显示你要更改的 DNS 解析记录值,设置好就可以完成更新了 Before continuing, verify the TXT record has been deployed. Depending on the DNS provider, this may take some time, from a few seconds to multiple minutes. You can check if it has finished deploying with aid of online tools, such as the Google Admin Toolbox: https://toolbox.googleapps.com/apps/dig/#TXT/_acme-challenge.jysahre.com. Look for one or more bolded line(s) below the line ';ANSWER'. It should show the value(s) you've just added. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -Other Extensions