Generate Free Let’s Encrypt SSL on Ubuntu 24.04
A Let’s Encrypt SSL certificate on Ubuntu 24.04 turns your website’s plain HTTP address into a secure HTTPS connection. This free security tool scrambles all data sent between your server and visitors so outsiders cannot steal passwords or personal details.
Certbot is the official command-line tool that requests and installs these certificates on your Linux server. Each certificate lasts for 90 days, but Certbot sets up automatic renewals so your site stays secure without any extra work from you.
Install Certbot with `sudo apt install certbot`, then run `sudo certbot certonly –webroot -w /var/www/html -d your_domain.com` for webroot or `sudo certbot certonly –standalone -d your_domain.com` for standalone.
Install Certbot Client
The Certbot client is a tool that automates the certificate process for Let’s Encrypt on Linux systems.
Run the command below to install it .
sudo apt update
sudo apt install certbot
With the tool now installed, you can generate certificates for your server.
Generate a certificate with a web server
You can generate a Let’s Encrypt SSL certificate on Ubuntu 24.04 while running an active web server like Apache or Nginx. Make sure your server is reachable from the internet on port 80. Then, run the command sudo certbot certonly –web in your terminal to complete the verification process and issue your new security certificate.
The command to generate a certificate is below, assuming a web server is installed.
sudo certbot certonly --webroot -w /var/www/html -d srv1.example.com
The command options:
- --webroot ==> [use a directory under webroot].
- -w /var/www/html ==> [working directory].
- -d ==> srv1.example.com [fully qualify server hostname].
When you press the enter key, you will see similar prompts like the ones below.
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Enter email address (used for urgent renewal and security notices)
# for only initial using, register your email address and agree to terms of use
# specify valid email address
(Enter 'c' to cancel): admin@example.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Please read the Terms of Service at
agree in order to register with the ACME server. Do you agree?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
# agree to the terms of use
(Y)es/(N)o: A
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Would you be willing, once your first certificate is successfully issued, to
EFF news, campaigns, and ways to support digital freedom.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(Y)es/(N)o: A
Account registered.
Requesting a certificate for srv1.example.com
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/srv1.example.com/fullchain.pem
Key is saved at: /etc/letsencrypt/live/srv1.example.com/privkey.pem
This certificate expires on 2025-03-10.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.
...........
...........
After generating your free SSL certificates, they will be stored at the location provided with the fully qualified server hostname. [/etc/letsencrypt/live/[severname]/]
Generate a certificate without a web server
You can generate a Let's Encrypt SSL certificate on Ubuntu 24.04 without running a web server by using the standalone mode. Temporarily stop any service using port 80, then run sudo certbot certonly --standalone -d srv1.example.com, replacing the domain with your actual server address. Certbot spins up a temporary web server to verify your domain and generate the files.
The command to do that is below.
sudo certbot certonly --standalone -d srv1.example.com
The command options:
- --standalone ==> [use web server features].
- -d ==> srv1.example.com [fully qualify server hostname].
If the command is successful, you will see a message similar to the one below.
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for srv1.example.com
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/srv1.example.com/fullchain.pem
Key is saved at: /etc/letsencrypt/live/srv1.example.com/privkey.pem
This certificate expires on 2025-03-10.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Your free SSL certificates should be ready to use.
Renewal
Let's Encrypt SSL certificates on Ubuntu 24.04 renew automatically because Certbot installs a background timer during setup. You do not need to perform manual renewals for your domains. To verify that this automatic background process is active and working properly, run the command systemctl status certbot.timer in your terminal to check the schedule.
There's nothing to do, it should automatically renew your certificates.
Run the command below to check its status.
systemctl status certbot.timer
You should see something similar to the one below.
* certbot.timer - Run certbot twice daily
Loaded: loaded (/usr/lib/systemd/system/certbot.timer; enabled; preset: en>
Active: active (waiting) since Mon 2025-03-10 10:13:26 UTC; 1min 17s ago
Trigger: Tue 2025-03-20 10:21:37 UTC; 14h left
Triggers: * certbot.service
To manually renew the certificates, run the command below.
sudo certbot renew
To convert certificates to PKCS12 (PFX) format for Windows and other systems, run the command below.
sudo openssl pkcs12 -export -in fullchain.pem -inkey privkey.pem -out srv1.example.com.pfx
That should do it!
Conclusion:
In summary, generating a free Let's Encrypt SSL certificate on Ubuntu 24.04 is a straightforward process that enhances your website's security. Here are the key points to remember:
- Free Service: Let's Encrypt provides cost-free SSL/TLS certificates to improve internet security.
- Automated Renewal: Certbot automates the certificate renewal process, ensuring your site remains secure without manual intervention.
- Flexible Options: Certificates can be generated with or without an existing web server, offering flexibility based on your server setup.
- Scheduled Tasks: Certbot creates system timers to manage the automatic renewal of certificates with minimal user input.
- PKCS12 Conversion: Certificates can be converted to different formats, such as PKCS12 (PFX), for wider compatibility across various systems.
By following the outlined steps, you can successfully secure your website with HTTPS, creating a safer online experience for your visitors.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
[…] you have already generated a SSL certificate, you can copy the certificates to the NetData directory specified in the config file […]
[…] Generate a free Let’s Encrypt SSL certificate […]