View Categories

Let’s Encrypt

This article will discuss on how to get certificates using let’s encrypt. In this article we are using ubuntu as an OS.

Let’s encrypt allows you to get certificates for your website for free with a minimal effort of proofing that you own the website. For that you need to proof that you have control over the website. Therefor the website must be reachable by the name for which you want to create the certificate for (e.g example uvuyo.2yetis.net) and you need to be able to install a small webserver (provided by let’s encrypt) so that let’s encrypt can contact this site and see if you have control over it.

To install the webserver run the following command on the ubuntu server where for which you want to create the certificate

sudo snap install certbot --classic

This will install the webserver.

Note
Don’t forget that your server must be reachable from the internet by the address you want to create the certificate for. So make sure you have the correct entries in your DNS Server.

After you have installed the webserver start it using the following command and answer the questions

sudo certbot certonly --standalone

When run successfull the certificates will be created and you will see a message simular to the following output on your screen

Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/uvuyo.on2yetis.net/fullchain.pem
Key is saved at:         /etc/letsencrypt/live/uvuyo.on2yetis.net/privkey.pem
This certificate expires on 2024-05-26.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
If you like Certbot, please consider supporting our work by:
 * Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
 * Donating to EFF:                    https://eff.org/donate-le
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Note
As mentioned in the output of the command the installation program will install a timer to regularly renew the certificate if needed.

To create a pkcs12 file which is used by uvuyo you will need to run the following command:

openssl pkcs12 -export \
-in fullchain.pem \
-inkey privkey.pem \
-out uvuyo.p12 \
-name uvuyo \
-CAfile chain.pem \
-caname root

The command will ask you for a password for the keystore. Remember the password since you will need it when you configure the keystore in uvuyo.

Nach oben