Welcome to Automating Let's Encrypt SSL Certificates with Certbot on Nginx. Manually renewing SSL certificates is a tedious and error-prone process that inevitably leads to an expired certificate taking down your production site. Let's look at how to automate this entirely.

1. The Let's Encrypt Revolution

Before Let's Encrypt, acquiring an SSL certificate meant paying a Certificate Authority (CA) and manually installing cryptographic files on your server every year. Let's Encrypt changed the web by providing free, automated, and open certificates. Their certificates are valid for 90 days, explicitly forcing administrators to automate the renewal process.

2. Introducing Certbot

Certbot is an open-source tool developed by the EFF (Electronic Frontier Foundation) that implements the ACME (Automated Certificate Management Environment) protocol. It talks to Let's Encrypt to prove you control a domain, downloads the certificate, and configures your web server to use itβ€”all automatically.

3. Installing Certbot for Nginx

On a modern Ubuntu/Debian system, you should install Certbot via snap to ensure you always have the latest version. After installing `snapd`, run sudo snap install --classic certbot, followed by preparing the command with sudo ln -s /snap/bin/certbot /usr/bin/certbot. Finally, you also need the Nginx plugin: sudo apt install python3-certbot-nginx.

4. Requesting the Certificate

Once your DNS A-records are pointing to your server, generating the certificate is as simple as running sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com. Certbot will read your Nginx server blocks, challenge the domains via HTTP-01 (placing a temporary file in your webroot), and if successful, modify your Nginx configuration files to include the new SSL paths.

5. Ensuring Auto-Renewal Works

The Certbot package automatically installs a systemd timer that runs twice a day. It checks if any certificates on the system are expiring within 30 days and renews them. You can test this automated process without actually touching your live certificates by running a dry-run: sudo certbot renew --dry-run. If this succeeds, you never have to worry about an expired SSL certificate again.

Conclusion

Automated SSL provisioning is a foundational requirement for any modern VPS deployment. By utilizing Certbot with Nginx, you secure your traffic and eliminate the human error associated with manual certificate management.