What you need to do to get an SSL certificate

To generate an SSL certificate, you create a certificate signing request (CSR) on your server, submit it to a certificate authority (CA), and then install the signed certificate back on your server. The whole process takes between a few minutes and a few days depending on the type of certificate and the CA you choose.

You have three main routes: buy a certificate from a commercial CA like DigiCert, Sectigo, or GoDaddy; use a free certificate from Let's Encrypt; or generate a self-signed certificate for testing. Most websites use Let's Encrypt or a paid CA. Self-signed certificates work for internal testing but browsers will warn visitors that the certificate is not trusted.

The steps differ slightly depending on your server software (Apache, Nginx, IIS) and hosting provider, but the underlying process is the same: generate a CSR, send it to a CA, receive a signed certificate, and configure your server to use it.

Key Takeaways

  • A certificate signing request (CSR) is a block of text your server generates that you send to a certificate authority to get signed.
  • Let's Encrypt offers free certificates that renew automatically and work with most hosting providers and server software.
  • Paid certificates from DigiCert, Sectigo, or GoDaddy offer longer validity periods and higher validation levels if your business needs them.
  • Self-signed certificates work for testing but will trigger browser warnings for visitors and should not be used on public websites.
  • Most hosting providers have built-in tools to generate and install certificates without command-line access.

Generating a certificate signing request on your server

A CSR is a text file that contains your domain name, company information, and a public key. Your server generates it using OpenSSL (on Linux and macOS) or IIS Manager (on Windows). The CA uses the CSR to create your signed certificate.

On Linux or macOS with Apache or Nginx, you generate a CSR by running an OpenSSL command in the terminal. The command asks for your domain name, country, state, city, and organization name. It creates two files: the CSR (which you send to the CA) and a private key (which stays on your server and never leaves it).

On Windows with IIS, you use IIS Manager to create a certificate request. Right-click your server name, select "Create Certificate Request", and fill in the same information. IIS saves the CSR to a text file on your computer.

If your hosting provider has a control panel like cPanel or Plesk, there is usually a "Generate SSL Certificate" or "Certificate Wizard" button that does this for you without needing terminal access. The panel generates the CSR, sends it to the CA, and installs the certificate automatically.

Using Let's Encrypt for free certificates

Let's Encrypt is a free certificate authority run by the Internet Security Research Group. It issues certificates valid for 90 days and requires you to renew them every three months. Most hosting providers and server software have built-in support for automatic renewal, so you set it up once and it renews without your involvement.

The easiest way to use Let's Encrypt is through Certbot, a tool that automates the entire process. If you have SSH access to your server, you install Certbot, run a single command with your domain name, and it generates the CSR, obtains the certificate, and installs it on your server. Certbot also sets up automatic renewal.

If your hosting provider supports Let's Encrypt (most do), you can generate and install a certificate directly from your control panel without touching the command line. Look for "Free SSL Certificate" or "Let's Encrypt" in your hosting dashboard. The provider handles the CSR and installation for you.

Let's Encrypt certificates work identically to paid certificates in browsers and provide the same encryption. The main difference is the 90-day renewal cycle and the fact that Let's Encrypt does not verify your business identity — it only confirms you control the domain.

Buying a certificate from a commercial certificate authority

Paid CAs like DigiCert, Sectigo, GoDaddy, and Comodo offer certificates with longer validity periods (usually one or two years), higher validation levels, and warranty coverage. You pay per certificate per year, with prices ranging from around $10 to several hundred dollars depending on the type.

The process is the same: you generate a CSR on your server, paste it into the CA's website during checkout, and complete payment. The CA then validates your domain ownership (usually by sending an email to an admin address or asking you to add a DNS record) and sends you the signed certificate within minutes to a few hours.

You then download the certificate and install it on your server. Most CAs provide installation instructions for common server software. Your hosting provider may also have a tool to paste the certificate directly into your control panel.

Paid certificates offer different validation levels: Domain Validation (DV) only confirms you own the domain, Organization Validation (OV) also verifies your business exists, and Extended Validation (EV) performs a thorough business check and displays your company name in the browser address bar. Most websites use DV certificates.

Installing the certificate on your server

Once you receive the signed certificate from the CA, you need to tell your server where to find it. The installation process depends on your server software and hosting setup.

On Apache, you edit the SSL configuration file (usually in /etc/apache2/sites-available/ or /etc/httpd/conf.d/) and point it to three files: the certificate file, the private key file, and sometimes an intermediate certificate file. Then you restart Apache.

On Nginx, you edit the server block in your configuration file and point it to the certificate and private key. Then you reload Nginx.

On Windows with IIS, you import the certificate into the certificate store using the Certificates snap-in, then bind it to your website in IIS Manager.

If you use a hosting control panel like cPanel, Plesk, or your provider's custom dashboard, there is usually a "Install SSL Certificate" button where you paste the certificate text and the panel handles the rest. This is the simplest route if it is available to you.

Self-signed certificates for testing

A self-signed certificate is one you sign yourself instead of having a CA sign it. It provides the same encryption as a CA-signed certificate but browsers do not recognize it as trusted, so visitors see a warning.

Self-signed certificates are useful for testing on a development server or internal network where you control the machines accessing the site. You generate one with a single OpenSSL command that creates both the certificate and private key in one step.

Do not use a self-signed certificate on a public website. Visitors will see a security warning, many will leave, and search engines may penalize the site. Use Let's Encrypt (free) or a paid CA instead.

Renewing and replacing certificates

Certificates expire and must be renewed before they stop working. Let's Encrypt certificates expire after 90 days, and paid certificates usually expire after one or two years. When a certificate expires, browsers show a security error and visitors cannot access your site.

If you use Let's Encrypt with Certbot or a hosting provider that supports automatic renewal, the certificate renews automatically before it expires. You do not need to do anything.

If you use a paid certificate, the CA sends you a reminder email before expiration. You then generate a new CSR, submit it to the CA, and install the new certificate. The process is identical to the initial certificate generation.

Some CAs offer multi-year certificates that you renew less often, but they still require manual renewal when they expire. Let's Encrypt is the only major CA that offers fully automatic renewal without any action on your part.

Frequently Asked Questions

What is the difference between a certificate and a private key?

The certificate is the public part that your server sends to browsers. The private key is secret and stays on your server — it proves you own the certificate and must never be shared. If someone gets your private key, they can impersonate your website.

Can I move a certificate to a different server?

Yes, but only if you have the private key file. The certificate and private key work as a pair. If you lose the private key, you must generate a new CSR and get a new certificate from the CA. Most CAs let you reissue a certificate for free if you lose it within the validity period.

Do I need a separate certificate for each subdomain?

No. A wildcard certificate (like *.example.com) covers all subdomains of a domain. A single-domain certificate covers only that domain. A multi-domain certificate (SAN certificate) covers multiple unrelated domains. Let's Encrypt and most paid CAs support all three types.

What happens if my certificate expires?

Browsers will show a security error and visitors cannot access your site. The site is not hacked or unsafe — the certificate just needs to be renewed. Renew it before expiration to avoid any downtime.

Is Let's Encrypt as secure as a paid certificate?

Yes. The encryption strength is identical. The difference is that Let's Encrypt does not verify your business identity and certificates expire every 90 days. For most websites, Let's Encrypt is the better choice because it is free and renews automatically.