SSL Certificates

SSL certificates and installation

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (9 sections)

This guide is for your own VPS, where you manage the web server yourself. It shows how to get a free Let's Encrypt certificate with Certbot on Nginx or Apache, how to install a certificate you bought elsewhere, and how to make sure renewal never fails silently. If your site is on Domain India shared hosting, you don't need any of this: free SSL is issued from your control panel.

Key takeaways

On a VPS, install Certbot, make sure your domain's A record points at the server and ports 80 and 443 are open, then run certbot --nginx or certbot --apache. Certbot installs the certificate and sets up automatic renewal; confirm it with certbot renew --dry-run. For a certificate bought from another authority, install the certificate, the intermediate chain and your private key in the web server config. Test the result with an external SSL checker.

On shared hosting? Use the panel instead

Domain India cPanel hosting issues free Let's Encrypt certificates automatically through AutoSSL, and DirectAdmin lets you request one from the panel. You can't run Certbot or change the web server config on shared hosting. See Ordering an SSL certificate.

1. Which certificate do you need?

TypeWhat is checkedTypical use
Domain validated (DV)Only that you control the domainAlmost every website, shop and API; Let's Encrypt issues DV
Organisation validated (OV)The domain plus your organisation's identityWhen a bank, tender or client explicitly asks for it
Extended validation (EV)A stricter organisation checkRarely needed today; browsers no longer show a special green bar
WildcardCovers *.example.comMany subdomains on one server; needs DNS validation

All of them encrypt traffic the same way. A free Let's Encrypt DV certificate is trusted by every current browser and is the right choice for most VPS sites. Domain India does not sell paid certificates; if you need an OV or EV certificate, buy it from a certificate authority and install it as shown in section 5.

2. Before you start

  1. Point the domain at the VPS.
    Create A records for @ and www (and AAAA records if the server has IPv6) with your server's IP address. Wait until dig A example.com +short returns that IP.
  2. Open ports 80 and 443.
    Let's Encrypt's HTTP check connects on port 80. With UFW: sudo ufw allow 'Nginx Full' or sudo ufw allow 'Apache Full'.
  3. Have a working site on port 80
    with a server block (Nginx) or virtual host (Apache) whose server_name or ServerName matches the domain.
  4. Check CAA records.
    If your domain has CAA records, one must allow letsencrypt.org.

3. Install Certbot and get a certificate

On Ubuntu or Debian, the distribution packages are the simplest route:

bash
sudo apt update
sudo apt install certbot python3-certbot-nginx     # Nginx
# or
sudo apt install certbot python3-certbot-apache    # Apache

Certbot's own site (certbot.eff.org) also documents a snap install and instructions for other distributions such as AlmaLinux and Rocky Linux.

Request and install the certificate in one step:

bash
sudo certbot --nginx -d example.com -d www.example.com
# or
sudo certbot --apache -d example.com -d www.example.com

Certbot proves you control the domain, saves the files under /etc/letsencrypt/live/example.com/, edits your server config and can add an HTTP-to-HTTPS redirect. If you would rather edit the config yourself, use certbot certonly --webroot -w /var/www/example -d example.com and point your server at the files.

4. Renewal: automate it and test it

Let's Encrypt certificates are valid for 90 days. Certificate lifetimes across the industry are being shortened in stages under CA/Browser Forum rules, so manual renewal is no longer realistic.

The packaged Certbot installs a systemd timer (or cron job) that checks twice a day and renews certificates close to expiry. Confirm it works:

bash
systemctl list-timers | grep certbot
sudo certbot renew --dry-run

The web server must reload to pick up a renewed certificate. The Nginx and Apache plugins handle this; with certonly, add a deploy hook:

bash
sudo certbot renew --deploy-hook "systemctl reload nginx"
Don't rely on expiry emails

Let's Encrypt stopped sending certificate expiry reminder emails in 2025. Monitor expiry yourself: a dry run after every server change, and an external uptime or certificate check that alerts you before the date.

Wildcard certificates

A wildcard needs a DNS-01 challenge: you prove control by publishing a TXT record at _acme-challenge.example.com. Certbot can do this automatically only with a DNS plugin for your DNS provider; with --manual you must add the record by hand at every renewal, which defeats automation.

5. Installing a certificate bought elsewhere

  1. Create a private key and CSR on the server:
bash
openssl req -new -newkey rsa:2048 -nodes \
  -keyout example.com.key -out example.com.csr \
  -subj "/CN=example.com"
  1. Submit the CSR to the certificate authority and complete its validation.
  2. Install the files. You receive the certificate and an intermediate chain (CA bundle). Keep the key readable only by root (chmod 600).

Nginx expects the certificate and chain in one file:

nginx
server {
    listen 443 ssl;
    server_name example.com www.example.com;
    ssl_certificate     /etc/ssl/example.com/fullchain.pem;  # certificate + intermediates
    ssl_certificate_key /etc/ssl/example.com/example.com.key;
    ssl_protocols TLSv1.2 TLSv1.3;
}

Apache 2.4.8 and later also accepts a full-chain file in SSLCertificateFile, with the key in SSLCertificateKeyFile. Test before reloading: sudo nginx -t or sudo apachectl configtest. Paid certificates need renewing too, before their expiry date; generating a fresh key and CSR for each renewal is good practice.

6. Check your installation

  • External test: Qualys SSL Labs' SSL Server Test grades your configuration and flags a missing intermediate chain.
  • From the command line: openssl s_client -connect example.com:443 -servername example.com shows the chain the server sends; curl -vI https://example.com shows the handshake.
  • Mixed content: if the padlock is missing on some pages, images or scripts are still loading over http://.

7. Common problems

SymptomLikely causeFix
Certbot says the challenge failedDomain not pointing at this server, or port 80 blockedCheck the A record and firewall, then retry
"Too many certificates already issued"Let's Encrypt rate limit after repeated attemptsTest with --dry-run or --staging and wait before retrying
Works in browsers, fails in apps or on phonesIntermediate chain missingServe the full chain file
Renewal succeeded but the site shows the old certificateWeb server not reloadedAdd a deploy hook that reloads the server

8. Where Domain India fits

Domain India VPS plans are self-managed: you get full root access and handle the web server, certificates and updates yourself. If you choose the free CyberPanel option at checkout, it has its own SSL tool. Prices are Domain India list prices on 19 September 2026, excluding 18% GST.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

If you would rather not manage certificates at all, shared hosting and the App Platform include free SSL that is issued and renewed for you. New to your VPS? Start with How to access your VPS using SSH and the SSH security hardening checklist.

Does Domain India sell paid SSL certificates?

No. Domain India hosting includes free Let's Encrypt SSL, and on a VPS you can install a free certificate with Certbot. If you need an OV or EV certificate, buy it from a certificate authority and install it on your server.

How long does a Let's Encrypt certificate last?

90 days. Certbot renews it automatically before it expires, so check that renewal works with certbot renew --dry-run.

Why did Certbot fail to issue my certificate?

Usually the domain does not point at the server yet, port 80 is blocked by a firewall, or a CAA record does not allow Let's Encrypt. Fix the cause and try again.

Can I get a free wildcard certificate?

Yes. Let's Encrypt issues wildcard certificates through a DNS-01 challenge, which needs a TXT record in your DNS. Use a Certbot DNS plugin for your DNS provider to automate renewal.

Do I need Certbot on Domain India shared hosting?

No. You cannot run it there. cPanel issues free certificates automatically through AutoSSL, and DirectAdmin lets you request a Let's Encrypt certificate from the panel.

How do I check that my SSL certificate is installed correctly?

Run your domain through an external test such as Qualys SSL Labs' SSL Server Test, which reports the certificate, the chain and the protocols your server offers.

Ready to secure your server? Choose a VPS for full control, or pick cPanel hosting where free SSL is automatic. For help, open a support ticket.

Get a VPS with full root access

Self-managed KVM servers where you control the web server, certificates and software.

See VPS plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app