Let's Encrypt Tutorial: Free SSL Certificate For Your Server
By NeuralNine
Key Concepts
- HTTPS (Hypertext Transfer Protocol Secure): A secure version of HTTP that encrypts communication between a web server and a user's browser.
- Let's Encrypt: A free, automated, and open certificate authority that provides SSL/TLS certificates.
- SSL/TLS Certificate: A digital certificate that authenticates a website's identity and enables encrypted communication.
- ACME (Automated Certificate Management Environment): A protocol used by clients to interact with certificate authorities for automated certificate management.
- Certificate Authority (CA): A trusted entity that issues digital certificates.
- Domain Name System (DNS): The hierarchical and decentralized naming system for computers, services, or any resource connected to the Internet or a private network.
- A Record (IPv4): A DNS record that maps a domain name to an IPv4 address.
- AAAA Record (IPv6): A DNS record that maps a domain name to an IPv6 address.
- VPS (Virtual Private Server): A virtual machine sold as a service by an Internet hosting service.
- Command Line Interface (CLI): A text-based interface used to operate software and operating systems.
- CertBot: A free, open-source software tool that automates the process of obtaining and renewing SSL/TLS certificates from Let's Encrypt.
- Standalone Mode: A CertBot mode where CertBot runs its own temporary web server on port 80 to handle the ACME challenge.
- Reverse Proxy: A server that sits in front of one or more web servers, forwarding client requests to the appropriate server.
- SSL Termination: The process of decrypting encrypted traffic at a point before it reaches the backend servers.
- Docker Compose: A tool for defining and running multi-container Docker applications.
- Nginx: A popular web server and reverse proxy.
- Virtual Environment: An isolated Python environment that allows you to manage dependencies for different projects separately.
- Gunicorn: A Python WSGI HTTP Server for UNIX.
Importance of HTTPS
The video emphasizes that HTTPS is a fundamental requirement for any website or web application. It serves two primary purposes:
- Trust and Reliability: An HTTPS connection makes a website appear trustworthy to users, which is crucial for customer confidence.
- Security Mechanism: It encrypts the traffic between the server and the user, protecting potentially sensitive information from being intercepted and read in plain text.
The presenter demonstrates the difference between HTTP and HTTPS by showing a web server accessible via an IP address. Initially, accessing the IP address directly or through a domain that doesn't have a corresponding certificate results in a "not secure" warning in the browser. However, when accessing a domain (floriandeoff.com) that has a valid Let's Encrypt certificate, the connection is marked as "secure," and the certificate details (issued by Let's Encrypt, valid until January 5th, 2026) are displayed. The goal of the tutorial is to enable this secure connection for another domain (openexodus.com) pointing to the same server.
Prerequisites for Setting Up Let's Encrypt
To follow this tutorial, users need:
- A Web Server: Preferably a VPS (Virtual Private Server).
- A Domain Name: Pointing to the VPS's IP address.
The presenter clarifies that the tutorial is for users with command-line access to their server, distinguishing it from simpler web hosting packages where SSL can often be enabled with a single click through a graphical user interface (GUI).
How Let's Encrypt Works (Theoretical Overview)
The video provides a brief theoretical explanation of how Let's Encrypt operates:
- Proof of Domain Control: The core principle is that a user must prove to a Certificate Authority (CA) that they control the domain for which they are requesting a certificate.
- ACME Protocol: This process is facilitated by the ACME protocol.
- Challenges: The CA issues a "challenge" to the user, typically by asking them to place a specific file at a designated path on their web server.
- Verification: The CA then attempts to access this file via the domain's URL. If successful, it confirms the user's control over the domain.
- Security Measures: To prevent abuse, the CA performs these checks from multiple network perspectives.
- Certificate Issuance: Upon successful verification, the CA issues a certificate, valid for a specific period, after which it needs to be renewed.
Step-by-Step Setup with CertBot
The tutorial then moves to the practical implementation using CertBot on a Ubuntu server.
1. SSH into the Server
The first step is to connect to the server via SSH. The presenter assumes the user is familiar with SSH connection methods (e.g., using IP addresses, key pairs, or passwords).
2. Install CertBot
The recommended method for installing CertBot is using Snap, but the presenter opts for apt on Ubuntu:
sudo apt install certbot
The presenter notes that CertBot is already installed on their system.
3. Obtain a Let's Encrypt Certificate
The core command to obtain a certificate using CertBot in standalone mode is:
sudo certbot certonly --standalone
certonly: This flag tells CertBot to only obtain the certificate and not to automatically configure a web server.--standalone: This mode starts a temporary web server on port 80 to handle the ACME challenge.
During the execution, CertBot prompts for the domain name. The presenter enters openexodus.com.
The command output shows:
- The temporary server starting.
- The CA providing and the client fulfilling the challenge.
- Successful certificate reception.
- The location where the certificate and private key are saved:
- Certificate:
/etc/letsencrypt/live/openexodus.com/fullchain.pem - Private Key:
/etc/letsencrypt/live/openexodus.com/privkey.pem
- Certificate:
- The certificate expiration date (January 5th, 2026).
4. Using the Certificate with Different Setups
The video then demonstrates two common scenarios for using the obtained certificate:
a) Basic Flask Application
This section shows how to configure a simple Flask application to serve traffic over HTTPS.
-
Prerequisites: A virtual environment is created, and Flask is installed.
-
app.py:from flask import Flask app = Flask(__name__) @app.route('/') def index(): return "hello https" if __name__ == '__main__': app.run( host='0.0.0.0', port=443, ssl_context=( '/etc/letsencrypt/live/openexodus.com/fullchain.pem', '/etc/letsencrypt/live/openexodus.com/privkey.pem' ) )host='0.0.0.0': Listens on all available network interfaces.port=443: The standard HTTPS port.ssl_context: A tuple containing the paths to the certificate and private key files.
-
Running the App:
python3 app.py -
Result: Accessing
openexodus.comnow shows "hello https" with a secure connection. Accessingfloriandeov.com(which points to the same IP but doesn't have the certificate configured for it in this Flask app) results in a "not private" warning.
b) Docker Compose with Nginx
This scenario uses Nginx as a reverse proxy to handle SSL termination and serve the Flask application.
-
Concept: Nginx will handle the HTTPS connection, decrypt the traffic (SSL termination), and then forward the unencrypted traffic to the Flask application running in a separate container.
-
docker-compose.yml:services: app: build: ./app ports: - "8000" # Internal port for Gunicorn expose: - "8000" nginx: image: nginx:latest ports: - "80:80" - "443:443" volumes: - ./nginx/default.conf:/etc/nginx/conf.d/default.conf:ro - /etc/letsencrypt:/etc/letsencrypt:ro # Read-only access to Let's Encrypt certificatesappservice: Builds the Flask application from the./appdirectory. It runs Gunicorn on port 8000 internally.nginxservice: Uses the latest Nginx image. It maps host ports 80 and 443 to the container. It mounts the Nginx configuration file and the Let's Encrypt certificate directory.
-
nginx/default.conf:server { listen 80; server_name openexodus.com www.openexodus.com; return 301 https://$host$request_uri; # Redirect HTTP to HTTPS } server { listen 443 ssl; server_name openexodus.com www.openexodus.com; ssl_certificate /etc/letsencrypt/live/openexodus.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/openexodus.com/privkey.pem; location / { proxy_pass http://app:8000; # Forward to the Flask app proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }- The first
serverblock handles HTTP requests on port 80 and redirects them to HTTPS. - The second
serverblock listens on port 443, enables SSL, and specifies the certificate and key paths. - The
location /block configures Nginx to act as a reverse proxy, forwarding requests to theappservice on port 8000.
- The first
-
app/app.py: A simplified Flask app without SSL configuration, as Nginx handles it.from flask import Flask app = Flask(__name__) @app.route('/') def index(): return "hello https" -
app/requirements.txt:Flask gunicorn -
Dockerfile(for the app service):FROM python:3.9-slim WORKDIR /app COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt COPY app.py . CMD ["gunicorn", "-w", "4", "-b", "0.0.0.0:8000", "app:app"] -
Building and Running:
docker compose build docker compose up -
Result: Accessing
openexodus.comshows "hello https" with a secure connection.
Certificate Renewal and Revocation
The video also covers essential management tasks:
Renewal
To renew a certificate:
sudo certbot renew --force-renew --cert-name openexodus.com
--force-renew: Forces renewal even if the certificate is not close to expiration.--cert-name: Specifies the certificate to renew.
The presenter chooses to run an HTTP server locally to fulfill the challenge during renewal.
Revocation
To revoke a certificate (e.g., if a private key is compromised):
sudo certbot revoke --cert-name openexodus.com
The command prompts for confirmation and offers to delete the associated certificate files. The presenter confirms and notes that this action will destroy current workflows.
Conclusion
The video concludes by reiterating the ease of setting up HTTPS with Let's Encrypt and CertBot. The presenter encourages viewers to like, subscribe, and check out their website for tutoring or freelancing services.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Why Does This Guy Appear In Kids Videos?
sphynx

TIC en las Organizaciones - Electiva Complementaria II Unisimon
Julieth Güell S

How to Tame Your Advice Monster | Michael Bungay Stanier | TED
TED

Margaret Heffernan: Why it's time to forget the pecking order at work
TED

The importance of psychological safety: Amy Edmondson
The King's Fund

What Is Psychological Safety?
Harvard Business Review

13-Conflict Management: Listening in Conflict
Deliberate Development