Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk4 min

Stop Paying for SSL Certificates: Get Free HTTPS with Let’s Encrypt and Certbot

Let’s Encrypt provides TLS certificates at no charge. Check your host’s HTTPS controls first; if it does not manage certificates, use Certbot with a validation method suited to your server and verify renewal.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can get a TLS certificate for your website at no charge from Let’s Encrypt. If your host does not manage HTTPS for you, Certbot can request a certificate and, on supported Apache or Nginx setups, install it. First check your hosting control panel: many hosts handle issuance and renewal without requiring you to run Certbot.

“SSL certificate” is the familiar term, but modern HTTPS uses TLS. Free certificate issuance does not make your whole website free: domain registration, hosting, and server administration may still cost money.

First check whether your host already manages HTTPS

Look in your hosting account for an HTTPS, SSL, or security setting, and check the provider’s instructions. If the host issues and renews certificates automatically, use its supported setup; installing a separate ACME client is usually unnecessary. Let’s Encrypt notes that some hosting platforms already provide HTTPS: Getting Started with Let’s Encrypt.

If your host does not offer managed HTTPS, find out whether you have command-line access and the privileges needed to configure the server. Shared-hosting customers often cannot administer the server as they would a virtual private server. In that case, ask the host about its certificate options or consider a hosting service that manages HTTPS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a validation and installation method

Certbot is an ACME client recommended by Let’s Encrypt for people who need to manage certificate issuance themselves. The right method depends on your operating system, web server, and network access. Use Certbot’s interactive instructions to select the current commands for your setup rather than treating one installation command as universal: Certbot instructions.

Method How it works Best fit and constraint
Apache or Nginx plugin Certbot proves control through the web server and can install the certificate by updating supported server configuration. Suitable when you run a supported Apache or Nginx setup and want Certbot to configure HTTPS.
Webroot Certbot places an HTTP challenge file in an existing website’s document root. Useful when the site is already serving files and you can provide its webroot path; HTTP validation needs the site reachable on port 80.
Standalone Certbot temporarily runs a server to answer the validation challenge. Useful when no web server plugin or existing webroot is being used; the required inbound connection must be available, and a service already using the port may need to be stopped temporarily.
DNS validation You prove control by creating a DNS record rather than serving an HTTP challenge from the site. Useful when inbound HTTP access is unavailable or you need a wildcard certificate. Automated DNS plugins may require separate installation and DNS credentials.

HTTP-01 validation depends on public reachability on port 80. DNS validation avoids an inbound connection to the server, but it is not automatically configured simply by installing Certbot; choose and configure a DNS plugin that supports your DNS provider. See Let’s Encrypt challenge types and the Certbot instructions.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Request and install the certificate

Certbot can either obtain a certificate alone or obtain and install it using a supported installer. The certonly option requests the certificate without changing the web-server configuration; choose an installer-enabled flow when you want Certbot to configure a supported Apache or Nginx server. Follow the commands generated for your operating system and server in the Certbot instruction selector.

  1. Confirm the domain and server. Make sure the domain you want covered points to the correct site and decide whether you will use an Apache/Nginx plugin, webroot, standalone, or DNS validation.
  2. Run the selected Certbot command. Use the current installation and issuance instructions for your operating system; commands and package defaults vary.
  3. Choose installation behavior. Let a supported installer update the server configuration, or use certonly and configure the server yourself.
  4. Check the result. Visit the site using https:// and confirm that the requested hostname loads with a valid certificate. If you used certonly, ensure the web server points to Certbot’s managed certificate files.

On standard Unix-like deployments, Certbot documents certificate files under /etc/letsencrypt/live/. That is a common location, not a universal path for every operating system or installation method. Prefer the managed paths in your web-server configuration rather than manually copying certificate files. See Certbot’s instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make renewal part of the setup

A certificate that is not renewed will eventually stop serving as a valid HTTPS certificate. Many Certbot installations create a scheduled task or timer, but the mechanism depends on how Certbot was installed. Check that your installation has a renewal schedule, then run a dry-run renewal test before relying on it. Certbot documents renewal testing at Renewing certificates.

  • Automated HTTP validation: Check that the scheduled task can still reach the site and complete validation.
  • DNS validation: Confirm that the configured plugin and credentials can update DNS when renewal runs.
  • Manual validation: A person must repeat the challenge unless authentication hooks automate it. Without hooks, manual issuance does not become automatic renewal.

Do not edit renewal settings casually. If you need to change them, keep a backup and follow the instructions for your Certbot installation.

Rank #4
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Test safely before changing production

Use Certbot’s dry-run renewal test to check the renewal process without making a production renewal. For initial experiments, Let’s Encrypt also provides a staging environment so you can test issuance without using production certificates. Staging certificates are for testing, not for securing a live site. See Let’s Encrypt’s staging environment documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.