Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Use Certbot’s Apache plugin to obtain a Let’s Encrypt certificate and, if you want, have Certbot update Apache to serve HTTPS. The standard Apache validation route requires your domain to point to the server and your HTTP site to be reachable publicly on port 80. If you need to keep control of Apache configuration, Certbot can obtain the certificate without editing the configuration for you.
Before you start
This procedure is for an administrator who controls an Apache server and a domain intended to serve from it. Confirm that the domain’s DNS records point to the intended server. For the Apache plugin route, the site also needs to be reachable from the public internet over HTTP on port 80. Certbot’s Apache instructions guide you through choosing Apache and then selecting the server’s operating system and installation method.
Install Certbot and its Apache plugin using the current instructions for your specific operating system and package source. Avoid mixing installation methods: different packages may install different Certbot executables or renewal mechanisms. Certbot’s Linux pip instructions show installation in a Python virtual environment, but describe this route as best effort; do not assume its commands apply to every distribution.
Choose how Certbot should handle Apache
| Command | What it does | Best suited to |
|---|---|---|
sudo certbot --apache |
Obtains a certificate and edits Apache configuration to serve the site over HTTPS. | Administrators whose active Apache configuration is suitable for Certbot to update. |
sudo certbot certonly --apache |
Obtains a certificate using the Apache plugin, without asking Certbot to make Apache configuration changes. | Administrators who want to configure or maintain Apache manually. |
These are Certbot’s documented Apache modes. See the official Apache instructions for the current prompts and operating-system-specific setup.
#1 Best Overall
Issue the certificate
- Check HTTP reachability. From outside your network, the domain should resolve to the server and its website should respond on port 80. If validation fails, verify DNS and that inbound HTTP traffic reaches Apache.
- Run the mode that matches your configuration needs. For automated Apache changes, run
sudo certbot --apache. For certificate issuance without automated Apache edits, runsudo certbot certonly --apache. - Follow Certbot’s prompts. Use the requested domain names and choices shown by the installed version. Prompt wording can vary with the installation and current Certbot instructions.
- Verify HTTPS. Visit the site using its HTTPS address and check that it loads. If you chose
certonly, configure the appropriate Apache virtual host yourself to use the issued certificate, then check the HTTPS site.
If HTTP validation cannot reach the server
Let’s Encrypt’s HTTP-based validation needs an inbound connection to the server on port 80. If that connection is unavailable, DNS validation is an alternative: it does not require Let’s Encrypt to connect inbound to the web server. DNS validation requires its own provider and credential setup, so follow the current Certbot DNS-plugin guidance for the provider and environment you use.
- If validation fails unexpectedly, confirm the domain resolves to the intended public endpoint and that port 80 reaches the Apache server.
- If inbound HTTP access cannot be provided, investigate DNS validation and its provider-specific setup rather than retrying the same Apache HTTP route.
- If Certbot behaves differently than expected, check which installation method supplied the executable and plugin, then use instructions for that exact operating system and package source.
Confirm automatic renewal
Issuing a certificate is only part of the setup: confirm that renewal is scheduled and that it works. Certbot’s snap instructions state that its packages include a cron job or systemd timer and identify locations to inspect. Check the mechanism appropriate to the package you installed; do not assume a timer or cron entry exists merely because Certbot is installed. Then run:
sudo certbot renew --dry-run
A successful dry run confirms that Certbot can carry out the renewal process in test mode. If it fails, inspect the reported error, verify that the installed plugin and configuration match the package you are using, and check the renewal schedule. Certbot’s Apache instructions and snap instructions provide package-specific guidance.
Quick Recap
Best Value
Rank #3
- Used Book in Good Condition
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




