There is no AutoSSL on a stock VPS. You install TLS on the server. Certbot talks to Let's Encrypt, proves you control the name, writes the certificate under /etc/letsencrypt/live/, and can reload Nginx or Apache for you.
This article is for a LochStudios KVM VPS. Credentials, the IPv4, and an out-of-band console sit on that server in the portal. Sign in at the portal, open the VPS service, and copy the login from there. Do not guess a hostname.
On Beginner and Standard shared hosting (cPanel), skip Certbot. Open the hosting service, click Log in to cPanel, then use SSL/TLS Status. AutoSSL issues a Let's Encrypt certificate once the name points at that account. Background: Understanding SSL/TLS and HTTPS.
On a dedicated server, open a support ticket if you want us to walk through a certificate with you.
A step is unclear? Open a support ticket and we will help.
Before you start
- Sign in at the portal, open the VPS service, and keep that page open. You need the IPv4.
- Connect with a sudo user, or
rooton a fresh box. See Connect to your VPS via SSH from macOS or Linux or from Windows. Prefer a sudo user: First steps on a new VPS. - Have Nginx or Apache serving the name on port 80.
- Nginx: Install Nginx on Ubuntu/Debian and Create an Nginx Server Block.
- Apache: Install Apache2 on Ubuntu/Debian and Set up Apache virtual hosts.
4. The A record for the name (and www if you want it on the certificate) must resolve to this VPS IPv4. Certbot proves control over HTTP on that address.
If SSH from your PC will not connect, open the console on the same service.
Point the name at this VPS
DNS for domains registered with us lives in the portal: Domains → the domain → DNS. AtlasDNS is the default. Do not send the name to a third-party DNS host.
Our nameservers:
ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
- Copy the VPS IPv4 from the server in the portal.
- On Domains → the domain → DNS, set an A record for
@(the apex) to that IPv4. - Point
wwwthe same way (another A, or a CNAME to the apex). - Save.
Full steps: Point your domain at your hosting. If the domain is registered elsewhere, set the three AtlasDNS nameservers first, then open a support ticket so we can put the zone on this account.
Check from the VPS:
dig +short yourdomain.com A
dig +short www.yourdomain.com A
The answer must be this VPS IPv4. Changes are often quick, but they can take a while to show everywhere. See DNS propagation explained.
Do not request a certificate until that lookup matches.
Open ports 80 and 443
Let's Encrypt checks port 80. Browsers use port 443 for HTTPS. Allow both on the host firewall. Do not enable UFW without SSH already allowed.
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw status
If UFW is still inactive, set it up properly first (SSH on 22, then 80 and 443): Set up a UFW firewall on Ubuntu.
The IPv4 on the VPS in the portal is the address Certbot must reach.
Install Certbot
On Ubuntu or Debian:
sudo apt update
sudo apt install certbot python3-certbot-nginx -y
If the site is on Apache:
sudo apt install certbot python3-certbot-apache -y
On AlmaLinux or Rocky Linux:
sudo dnf install epel-release -y
sudo dnf install certbot python3-certbot-nginx -y
Use python3-certbot-apache instead of the Nginx plugin if Apache is the web server.
Issue and install the certificate
Replace yourdomain.com with the real name. Include every hostname you want on this certificate.
Nginx (issues the cert and updates the server block):
sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com
Apache:
sudo certbot --apache -d yourdomain.com -d www.yourdomain.com
Certbot asks for an email (Let's Encrypt uses it for expiry notices), agreement to the Let's Encrypt terms, and whether to redirect HTTP to HTTPS. Choose the redirect unless you have a reason not to.
The files land in /etc/letsencrypt/live/yourdomain.com/:
fullchain.pemis the certificate plus chainprivkey.pemis the private key
Leave those paths as Certbot wrote them. Do not copy the key into the site document root.
Certificate only (you will edit the vhost yourself):
sudo certbot certonly --nginx -d yourdomain.com -d www.yourdomain.com
Use --apache the same way, or --webroot -w /var/www/yourdomain.com/html if Certbot should not edit the web server config. --standalone only works when nothing else is bound to port 80.
Check the certificate
sudo certbot certificates
You should see the names, the expiry (Let's Encrypt issues for 90 days), and the path.
Then visit https://yourdomain.com and https://www.yourdomain.com in a private window. You want a padlock, not Not secure.
echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null | openssl x509 -noout -subject -dates
A lock with mixed-content warnings is a different job: Fix "Not secure" and mixed-content warnings.
If you used certonly, point the web server at the files
Nginx (/etc/nginx/sites-available/yourdomain.com):
server {
listen 443 ssl http2;
server_name yourdomain.com www.yourdomain.com;
ssl_certificate /etc/letsencrypt/live/yourdomain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/yourdomain.com/privkey.pem;
# The rest of your existing server block (root, index, location) stays here.
}
server {
listen 80;
server_name yourdomain.com www.yourdomain.com;
return 301 https://$host$request_uri;
}
Then:
sudo nginx -t
sudo systemctl reload nginx
Apache:
sudo a2enmod ssl
In the vhost (for example /etc/apache2/sites-available/yourdomain.com.conf):
<VirtualHost *:443>
ServerName yourdomain.com
ServerAlias www.yourdomain.com
SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/yourdomain.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/yourdomain.com/privkey.pem
# The rest of your existing VirtualHost stays here.
</VirtualHost>
<VirtualHost *:80>
ServerName yourdomain.com
ServerAlias www.yourdomain.com
Redirect / https://yourdomain.com/
</VirtualHost>
Then:
sudo apache2ctl configtest
sudo systemctl reload apache2
Keep renewal running
Let's Encrypt certificates last 90 days. Certbot installs a systemd timer that checks twice daily and renews when fewer than 30 days remain. You do not mark a calendar date.
sudo systemctl enable --now certbot.timer
sudo systemctl status certbot.timer
Dry-run (does not replace a still-valid cert):
sudo certbot renew --dry-run
If the dry-run finishes cleanly, automatic renewal is in good shape.
Do not run sudo certbot renew --force-renewal unless you have a reason. Let's Encrypt limits how often the same name can be issued.
--manual does not renew on its own. Prefer --nginx or --apache for names that already resolve here.
Extra names and wildcards
Add another hostname with another -d:
sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com -d app.yourdomain.com
Each of those names needs an A record (or a CNAME that ends at this IPv4) before you run Certbot.
A *.yourdomain.com wildcard needs a DNS text check, not HTTP. That is more work than listing the names you actually use. Prefer listing them.
If you do need a wildcard:
- Keep the zone on AtlasDNS (Domains → the domain → DNS).
- Run:
```bash
sudo certbot certonly --manual --preferred-challenges dns -d yourdomain.com -d '*.yourdomain.com'
```
- When Certbot prints a
_acme-challengeTXT value, add that record on the DNS page, wait untildig +short TXT _acme-challenge.yourdomain.comshows it, then continue.
Manual mode will not renew itself. Re-run before the 90 days are up, or open a support ticket and we will plan a layout that can renew.
Skip CAA records unless you have a reason. A CAA that names the wrong issuer stops Let's Encrypt. If you want one set, open a support ticket. See DNS record types explained.
If it did not work
Work through these in order:
- Wrong A record.
dig +short yourdomain.com Amust be the IPv4 on the VPS in the portal. - Port 80 is closed.
sudo ufw statusshould allow 80/tcp and 443/tcp. The web server must be running:sudo systemctl status nginxorsudo systemctl status apache2. - The name is not in the vhost.
server_name/ServerNamemust match the-dvalues. - Something else holds port 80.
sudo ss -tlnp | grep ':80'should show Nginx or Apache, not another process you forgot about. - The site is in Docker and the host has no process on 80. Publish 80 and 443 to the container, or open a support ticket and we will walk through that layout.
If Certbot still cannot issue the certificate, open a support ticket. Tell us the domain and the VPS service. Paste the Certbot output (no private keys). Do not send the password in the ticket.
Website HTTPS is not mailbox TLS. Mail on this VPS is a different product from LochStudios Mail and from cPanel mail.
Need a VPS first? See VPS. Shared hosting with AutoSSL is at shared hosting.