Installing an SSL Certificate on a Domain Using Certbot manually
1. Install Certbot
If Certbot is not already installed, you can install it using the following commands:
For Debian/Ubuntu:
sudo apt update
sudo apt install certbot
2. Obtain the SSL Certificate
export DOMAIN=<your domain>
certbot certonly --manual -d *.$DOMAIN -d $DOMAIN --agree-tos --manual-public-ip-logging-ok --preferred-challenges dns-01 --server --register-unsafely-without-email --rsa-key-size 4096
3. Certbot will provide instructions on how to create a DNS TXT record to verify your domain ownership. The output will look something like this:
Please deploy a DNS TXT record under the name with the following value:
Before continuing, verify the record is deployed.
After creating the DNS TXT record, wait for the changes to propagate. This can
take a few minutes. You can verify the DNS record by using a tool like
to ensure it has been properly set.
4. Setup ssl
Your new SSL certificates will be stored in the /etc/letsencrypt/live/$DOMAIN/ directory. You will find the following files:
server {
listen 443 ssl;
ssl_certificate /etc/letsencrypt/live/;
ssl_certificate_key /etc/letsencrypt/live/;
location / {
root /var/www/html;
index index.html index.htm;