Here is how I install Certbot, generate a Let’s Encrypt certificate, and use it in an Nginx site. I use example.com as a placeholder domain.
Installation
sudo apt-get updatesudo apt-get install -y software-properties-commonsudo add-apt-repository ppa:certbot/certbotsudo apt-get updatesudo apt-get install -y python-certbot-nginxCreate a New Certificate
sudo certbot certonly --webroot -w /var/www/example.com/public -d example.com -d www.example.com -n -m you@example.com --agree-tos
# --webroot => Use webroot plugin# -w => The web root path# -d => The domain name# -n => The non-interactive mode# -m => Email address for notification# --agree-tos => Agree to TOSNginx SSL Setup
The site should be up and running first before generating a certificate with the webroot plugin.
# Generate certificatesudo certbot certonly --webroot -w /var/www/example.com/public -d example.com -d www.example.com -n -m you@example.com --agree-tos
# Create symlink for SSLsudo ln -sfv /etc/letsencrypt/live/example.com /etc/nginx/ssl/
# Generate DHE chippers if not yet availablesudo openssl dhparam -out /etc/nginx/ssl/dhparam.pem 4096
# Copy configurationsudo cp /etc/nginx/sites-example/site-ssl.conf /etc/nginx/sites-available/example.com
# Edit in vimsudo vim /etc/nginx/sites-available/example.com:%s/example.com/YOUR_DOMAIN/gc # Replace command
# Create symlink for site configuration (if not yet existed)sudo ln -sfv /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled
# Test configurationsudo nginx -t
# Reload configurationsudo service nginx reloadThe sites-example/site-ssl.conf file comes from my own Nginx configuration repository. The vim replace command swaps the example.com placeholder in that template for the real domain (YOUR_DOMAIN here).
Other Useful Commands
# List all certificatessudo certbot certificates
# Revoke certificatesudo certbot revoke --cert-path /etc/letsencrypt/live/example.com/cert.pem
# Delete certiciate completely# If certificate is revoked but not deleted, it will be renewed on the next renewal attemptsudo certbot delete --cert-name example.com