Cloud

Install a Free SSL Certificate on Your Cloud Server

Get HTTPS on your cloud server for free using Let's Encrypt and Certbot in under 10 minutes, with automatic renewal included.

Detailed image of illuminated server racks showcasing modern technology infrastructure.

Installing an SSL certificate on a cloud server is free and takes less than 10 minutes using Let's Encrypt and the Certbot tool. The result is browser-trusted HTTPS with automatic renewal every 90 days at no cost.

Why You Need SSL on Your Cloud Server

HTTPS is no longer optional. Google penalizes sites without SSL in search rankings, modern browsers show "Not Secure" warnings, and users abandon pages that don't encrypt their connection. On your own cloud server, the SSL certificate is your responsibility—and the good news is you don't have to pay a cent.

For context on which cloud hosting plans include automatic SSL, check out our dedicated category.

Prerequisites

Before running any commands, make sure you have:

  • A cloud server with SSH access and a user with sudo privileges.
  • A domain pointing to the server's IP address (active and propagated A or CNAME record).
  • Apache or Nginx installed and serving the domain on port 80.
  • Ports 80 and 443 open in the server firewall (firewalld, ufw, or the provider's security group).

If the domain doesn't resolve to the server's IP, Let's Encrypt won't be able to validate domain ownership and the process will fail.

Installing Certbot Step by Step

On Debian/Ubuntu-Based Distributions

sudo apt update
sudo apt install certbot python3-certbot-nginx -y   # for Nginx
# or
sudo apt install certbot python3-certbot-apache -y  # for Apache

On RHEL/AlmaLinux/Rocky-Based Distributions

sudo dnf install epel-release -y
sudo dnf install certbot python3-certbot-nginx -y   # for Nginx
# or
sudo dnf install certbot python3-certbot-apache -y  # for Apache

Obtaining and Installing the Certificate

With Certbot installed, a single command requests the certificate, edits your web server configuration, and automatically enables HTTP → HTTPS redirection:

For Nginx

sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com

For Apache

sudo certbot --apache -d yourdomain.com -d www.yourdomain.com

Certbot will ask for your email address (for expiry notifications) and prompt you to accept the terms of service. It then validates the domain via an HTTP-01 challenge—placing a temporary file on your server for Let's Encrypt to verify remotely.

When done, Certbot confirms the path where it saved the certificate files:

File Typical Path Purpose
fullchain.pem /etc/letsencrypt/live/yourdomain.com/ Certificate + intermediate chain
privkey.pem /etc/letsencrypt/live/yourdomain.com/ Private key

Setting Up Automatic Renewal

Let's Encrypt certificates expire every 90 days. Certbot automatically installs a systemd timer (or cron entry) that attempts renewal twice a day. Verify it's active:

sudo systemctl status certbot.timer   # on systemd systems
# or check cron:
sudo crontab -l

To simulate a renewal without actually running it and confirm everything is working:

sudo certbot renew --dry-run

If the dry-run returns Congratulations, all renewals succeeded, automatic renewal is correctly configured.

Verifying That HTTPS Works

After installation, check the result with these tools:

  • SSL Labs (ssllabs.com/ssltest): Full TLS configuration analysis. Aim for at least an A grade.
  • curl in terminal: curl -I https://yourdomain.com — should return 200 OK with Strict-Transport-Security headers.
  • Browser: The padlock icon in the address bar confirms the certificate is valid and trusted.

If the site still responds on HTTP, check that Certbot added the redirect in your Nginx or Apache config, or add it manually with a return 301 https://$host$request_uri; block.

If your business needs a more robust TLS setup—with HSTS headers, OCSP stapling, and advanced security policies— the specialists at elenlace.com can configure it from scratch for you.

Key Takeaways

  • Let's Encrypt + Certbot deliver a valid, free SSL certificate with automatic renewal in under 10 minutes.
  • The domain must point to the server's IP before running Certbot; without DNS resolution, validation will fail.
  • Use certbot --dry-run to confirm automatic renewal is working correctly.
  • Verify your TLS configuration quality on SSL Labs — aim for an A grade or higher.
  • HTTPS is now a requirement for SEO, user trust, and basic security compliance.

Want your cloud server configured with SSL, hardened security, and optimized performance from day one? Contact elenlace.com and we'll have it ready in hours.

FAQ

Is Let's Encrypt really free forever?

Yes. Let's Encrypt is a non-profit certificate authority funded by the tech industry. There's no cost for certificates and no time limit; the only requirement is renewing every 90 days, which Certbot handles automatically.

Does it work with any cloud server provider?

It works with any cloud server that has SSH access, runs Linux, and allows traffic on ports 80 and 443. It's compatible with AWS, Google Cloud, DigitalOcean, Linode, Hetzner, and any other provider.

What happens if the certificate expires without renewing?

The browser shows a "Your connection is not private" error and blocks access to the site. That's why it's critical to keep Certbot's automatic renewal timer active. Configure email alerts in Certbot so you're notified if a renewal fails.

Can I install SSL on a subdomain separately?

Yes. Add the subdomain with the -d subdomain.yourdomain.com flag in the Certbot command. You can also request wildcard certificates (*.yourdomain.com), though these require the DNS-01 challenge instead of HTTP-01 and additional configuration.

Useful resources

Other providers and guides worth comparing:

← All