Let's Encrypt Tutorial: Free SSL Certificate For Your Server

By NeuralNine

Share:

Key Concepts

  • HTTPS (Hypertext Transfer Protocol Secure): A secure version of HTTP that encrypts communication between a web server and a user's browser.
  • Let's Encrypt: A free, automated, and open certificate authority that provides SSL/TLS certificates.
  • SSL/TLS Certificate: A digital certificate that authenticates a website's identity and enables encrypted communication.
  • ACME (Automated Certificate Management Environment): A protocol used by clients to interact with certificate authorities for automated certificate management.
  • Certificate Authority (CA): A trusted entity that issues digital certificates.
  • Domain Name System (DNS): The hierarchical and decentralized naming system for computers, services, or any resource connected to the Internet or a private network.
  • A Record (IPv4): A DNS record that maps a domain name to an IPv4 address.
  • AAAA Record (IPv6): A DNS record that maps a domain name to an IPv6 address.
  • VPS (Virtual Private Server): A virtual machine sold as a service by an Internet hosting service.
  • Command Line Interface (CLI): A text-based interface used to operate software and operating systems.
  • CertBot: A free, open-source software tool that automates the process of obtaining and renewing SSL/TLS certificates from Let's Encrypt.
  • Standalone Mode: A CertBot mode where CertBot runs its own temporary web server on port 80 to handle the ACME challenge.
  • Reverse Proxy: A server that sits in front of one or more web servers, forwarding client requests to the appropriate server.
  • SSL Termination: The process of decrypting encrypted traffic at a point before it reaches the backend servers.
  • Docker Compose: A tool for defining and running multi-container Docker applications.
  • Nginx: A popular web server and reverse proxy.
  • Virtual Environment: An isolated Python environment that allows you to manage dependencies for different projects separately.
  • Gunicorn: A Python WSGI HTTP Server for UNIX.

Importance of HTTPS

The video emphasizes that HTTPS is a fundamental requirement for any website or web application. It serves two primary purposes:

  1. Trust and Reliability: An HTTPS connection makes a website appear trustworthy to users, which is crucial for customer confidence.
  2. Security Mechanism: It encrypts the traffic between the server and the user, protecting potentially sensitive information from being intercepted and read in plain text.

The presenter demonstrates the difference between HTTP and HTTPS by showing a web server accessible via an IP address. Initially, accessing the IP address directly or through a domain that doesn't have a corresponding certificate results in a "not secure" warning in the browser. However, when accessing a domain (floriandeoff.com) that has a valid Let's Encrypt certificate, the connection is marked as "secure," and the certificate details (issued by Let's Encrypt, valid until January 5th, 2026) are displayed. The goal of the tutorial is to enable this secure connection for another domain (openexodus.com) pointing to the same server.

Prerequisites for Setting Up Let's Encrypt

To follow this tutorial, users need:

  • A Web Server: Preferably a VPS (Virtual Private Server).
  • A Domain Name: Pointing to the VPS's IP address.

The presenter clarifies that the tutorial is for users with command-line access to their server, distinguishing it from simpler web hosting packages where SSL can often be enabled with a single click through a graphical user interface (GUI).

How Let's Encrypt Works (Theoretical Overview)

The video provides a brief theoretical explanation of how Let's Encrypt operates:

  • Proof of Domain Control: The core principle is that a user must prove to a Certificate Authority (CA) that they control the domain for which they are requesting a certificate.
  • ACME Protocol: This process is facilitated by the ACME protocol.
  • Challenges: The CA issues a "challenge" to the user, typically by asking them to place a specific file at a designated path on their web server.
  • Verification: The CA then attempts to access this file via the domain's URL. If successful, it confirms the user's control over the domain.
  • Security Measures: To prevent abuse, the CA performs these checks from multiple network perspectives.
  • Certificate Issuance: Upon successful verification, the CA issues a certificate, valid for a specific period, after which it needs to be renewed.

Step-by-Step Setup with CertBot

The tutorial then moves to the practical implementation using CertBot on a Ubuntu server.

1. SSH into the Server

The first step is to connect to the server via SSH. The presenter assumes the user is familiar with SSH connection methods (e.g., using IP addresses, key pairs, or passwords).

2. Install CertBot

The recommended method for installing CertBot is using Snap, but the presenter opts for apt on Ubuntu:

sudo apt install certbot

The presenter notes that CertBot is already installed on their system.

3. Obtain a Let's Encrypt Certificate

The core command to obtain a certificate using CertBot in standalone mode is:

sudo certbot certonly --standalone
  • certonly: This flag tells CertBot to only obtain the certificate and not to automatically configure a web server.
  • --standalone: This mode starts a temporary web server on port 80 to handle the ACME challenge.

During the execution, CertBot prompts for the domain name. The presenter enters openexodus.com.

The command output shows:

  • The temporary server starting.
  • The CA providing and the client fulfilling the challenge.
  • Successful certificate reception.
  • The location where the certificate and private key are saved:
    • Certificate: /etc/letsencrypt/live/openexodus.com/fullchain.pem
    • Private Key: /etc/letsencrypt/live/openexodus.com/privkey.pem
  • The certificate expiration date (January 5th, 2026).

4. Using the Certificate with Different Setups

The video then demonstrates two common scenarios for using the obtained certificate:

a) Basic Flask Application

This section shows how to configure a simple Flask application to serve traffic over HTTPS.

  • Prerequisites: A virtual environment is created, and Flask is installed.

  • app.py:

    from flask import Flask
    
    app = Flask(__name__)
    
    @app.route('/')
    def index():
        return "hello https"
    
    if __name__ == '__main__':
        app.run(
            host='0.0.0.0',
            port=443,
            ssl_context=(
                '/etc/letsencrypt/live/openexodus.com/fullchain.pem',
                '/etc/letsencrypt/live/openexodus.com/privkey.pem'
            )
        )
    
    • host='0.0.0.0': Listens on all available network interfaces.
    • port=443: The standard HTTPS port.
    • ssl_context: A tuple containing the paths to the certificate and private key files.
  • Running the App: python3 app.py

  • Result: Accessing openexodus.com now shows "hello https" with a secure connection. Accessing floriandeov.com (which points to the same IP but doesn't have the certificate configured for it in this Flask app) results in a "not private" warning.

b) Docker Compose with Nginx

This scenario uses Nginx as a reverse proxy to handle SSL termination and serve the Flask application.

  • Concept: Nginx will handle the HTTPS connection, decrypt the traffic (SSL termination), and then forward the unencrypted traffic to the Flask application running in a separate container.

  • docker-compose.yml:

    services:
      app:
        build: ./app
        ports:
          - "8000" # Internal port for Gunicorn
        expose:
          - "8000"
    
      nginx:
        image: nginx:latest
        ports:
          - "80:80"
          - "443:443"
        volumes:
          - ./nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
          - /etc/letsencrypt:/etc/letsencrypt:ro # Read-only access to Let's Encrypt certificates
    
    • app service: Builds the Flask application from the ./app directory. It runs Gunicorn on port 8000 internally.
    • nginx service: Uses the latest Nginx image. It maps host ports 80 and 443 to the container. It mounts the Nginx configuration file and the Let's Encrypt certificate directory.
  • nginx/default.conf:

    server {
        listen 80;
        server_name openexodus.com www.openexodus.com;
        return 301 https://$host$request_uri; # Redirect HTTP to HTTPS
    }
    
    server {
        listen 443 ssl;
        server_name openexodus.com www.openexodus.com;
    
        ssl_certificate /etc/letsencrypt/live/openexodus.com/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/openexodus.com/privkey.pem;
    
        location / {
            proxy_pass http://app:8000; # Forward to the Flask app
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    
    • The first server block handles HTTP requests on port 80 and redirects them to HTTPS.
    • The second server block listens on port 443, enables SSL, and specifies the certificate and key paths.
    • The location / block configures Nginx to act as a reverse proxy, forwarding requests to the app service on port 8000.
  • app/app.py: A simplified Flask app without SSL configuration, as Nginx handles it.

    from flask import Flask
    
    app = Flask(__name__)
    
    @app.route('/')
    def index():
        return "hello https"
    
  • app/requirements.txt:

    Flask
    gunicorn
    
  • Dockerfile (for the app service):

    FROM python:3.9-slim
    
    WORKDIR /app
    
    COPY requirements.txt .
    RUN pip install --no-cache-dir -r requirements.txt
    
    COPY app.py .
    
    CMD ["gunicorn", "-w", "4", "-b", "0.0.0.0:8000", "app:app"]
    
  • Building and Running:

    docker compose build
    docker compose up
    
  • Result: Accessing openexodus.com shows "hello https" with a secure connection.

Certificate Renewal and Revocation

The video also covers essential management tasks:

Renewal

To renew a certificate:

sudo certbot renew --force-renew --cert-name openexodus.com
  • --force-renew: Forces renewal even if the certificate is not close to expiration.
  • --cert-name: Specifies the certificate to renew.

The presenter chooses to run an HTTP server locally to fulfill the challenge during renewal.

Revocation

To revoke a certificate (e.g., if a private key is compromised):

sudo certbot revoke --cert-name openexodus.com

The command prompts for confirmation and offers to delete the associated certificate files. The presenter confirms and notes that this action will destroy current workflows.

Conclusion

The video concludes by reiterating the ease of setting up HTTPS with Let's Encrypt and CertBot. The presenter encourages viewers to like, subscribe, and check out their website for tutoring or freelancing services.

Chat with this Video

AI-Powered

Load the transcript when you're ready to chat so the initial page stays lighter.

Ready to summarize another video?

Summarize YouTube Video