---
title: "SSL certificate on a VPS with Let's Encrypt and Nginx | StreetHosting"
description: "Install Certbot, issue free HTTPS, set up automatic renewal, multiple domains and security headers on an Ubuntu VPS in Brazil."
url: "https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps"
type: "page"
language: "en-US"
---

VPS · 4 min · Beginner

Published on Jun 11, 2026 · Updated on Jun 11, 2026

# Let's Encrypt SSL on a VPS with Nginx

A site without the padlock loses trust and rankings. This guide shows how to issue, renew and audit a free SSL certificate on your VPS with Nginx and Certbot.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Certificates and HTTPS](https://streethosting.com.br/en/guides/topics/ssl) [Linux administration](https://streethosting.com.br/en/guides/topics/linux) [Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=SSL%20certificate%20on%20a%20VPS%20with%20Let%27s%20Encrypt%20and%20Nginx&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps "Share on LinkedIn") [](https://wa.me/?text=SSL%20certificate%20on%20a%20VPS%20with%20Let%27s%20Encrypt%20and%20Nginx%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Flets-encrypt-ssl-certificate-vps "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps.md)

In this guide 5 sections

* [What SSL is and why it matters](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#o-que-e-ssl)
* [VPS prerequisites](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#pre-requisitos)
* [Install Certbot and Nginx](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#instalar-certbot)
* [Multiple domains and renewal](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#varios-dominios)
* [Troubleshooting and auditing](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#troubleshooting)

Quick answer

For an **SSL certificate on a VPS**, install **Certbot** with the Nginx plugin, point your DNS at the VPS IP, run **certbot --nginx** and confirm **automatic renewal**. Redirect HTTP to HTTPS and test with **certbot renew --dry-run** before going to production.

## What SSL is and why it matters[](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#o-que-e-ssl)

SSL (today TLS) encrypts the traffic between the browser and the server. Google favors HTTPS, browsers flag HTTP as insecure and payment gateways require a store with a valid padlock. On a root VPS you issue and renew the certificate yourself, with no need to pay a commercial CA in most cases.

| Situation    | Without SSL            | With Let's Encrypt      |
| ------------ | ---------------------- | ----------------------- |
| Online store | Checkout abandonment   | Trust and PCI alignment |
| REST API     | Exposed token          | Encrypted traffic       |
| Admin panel  | Password in clear text | Protected session       |
| SEO          | Negative signal        | HTTPS as the baseline   |

WooCommerce stores in Brazil should pair SSL with the stack described in [VPS for ecommerce](https://streethosting.com.br/en/guides/vps/vps-for-ecommerce-brazil).

## VPS prerequisites[](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#pre-requisitos)

* Ubuntu or Debian VPS with root or sudo
* Domain with an A record pointing to the VPS public IP
* Ports 80 and 443 open in the firewall
* Nginx installed with a basic server block for the domain
* Secure SSH configured before exposing any services

Set up the firewall with [UFW on the VPS](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) and follow [secure SSH](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps) right after you sign up for one of the [StreetHosting VPS plans](https://streethosting.com.br/en/vps).

DNS propagation can take up to 48 hours at some registrars. Validate with dig +short seudominio.com.br before running Certbot.

## Install Certbot and Nginx[](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#instalar-certbot)

### Installing on Ubuntu

1. sudo apt update && sudo apt install certbot python3-certbot-nginx
2. Create a server block in /etc/nginx/sites-available/ with server\_name and root
3. sudo ln -s sites-available/site sites-enabled/
4. sudo nginx -t && sudo systemctl reload nginx

### Issuing the certificate

With Nginx answering on port 80, run the integrated issuance:

* sudo certbot --nginx -d seudominio.com.br -d www.seudominio.com.br
* Choose the automatic HTTP to HTTPS redirect when prompted
* Confirm the files in /etc/letsencrypt/live/seudominio.com.br/

| Command                        | Use                                          |
| ------------------------------ | -------------------------------------------- |
| certbot certificates           | List certificates and their expiry           |
| certbot renew --dry-run        | Simulate renewal without touching production |
| nginx -t                       | Validate syntax before a reload              |
| systemctl status certbot.timer | Confirm the renewal timer                    |

### Recommended security headers

Once SSL is active, add these to the HTTPS server block: Strict-Transport-Security, X-Frame-Options and X-Content-Type-Options. They strengthen trust on stores and admin panels.

## Multiple domains and renewal[](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#varios-dominios)

Agencies and makers with several projects on the same VPS issue one certificate per domain. The full structure is in [multiple sites on the same VPS with Nginx](https://streethosting.com.br/en/guides/vps/multiple-websites-on-one-vps).

### Automatic renewal

Let's Encrypt certificates last 90 days. Ubuntu installs a systemd timer that renews them when 30 days are left. Confirm it with systemctl list-timers | grep certbot and schedule a monthly reminder for a manual dry run.

### n8n automation and webhooks

Workflows on a [Ryzen VPS](https://streethosting.com.br/en/vps/ryzen) that receive external webhooks also need HTTPS. Issue the certificate on the n8n.seudominio.com.br subdomain and restrict access by IP or VPN when possible.

* One independent certificate per critical domain
* Consistent www and apex redirect
* Let's Encrypt staging certificate for CI tests
* Backup of /etc/letsencrypt before rebuilding the VPS

## Troubleshooting and auditing[](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#troubleshooting)

| Common error                 | Likely cause              | Fix                                   |
| ---------------------------- | ------------------------- | ------------------------------------- |
| Connection refused port 80   | Firewall or Nginx stopped | ufw allow 80 && systemctl start nginx |
| DNS problem NXDOMAIN         | Missing A record          | Fix the DNS and wait for the TTL      |
| Too many requests            | Let's Encrypt rate limit  | Wait 1h or use staging                |
| Mixed content in the browser | Assets served over HTTP   | Force HTTPS on internal URLs          |
| Expired certificate          | Timer disabled            | certbot renew && reload nginx         |

### Periodic audit

* Run an external test with SSL Labs or similar every quarter
* Check the full chain served by Nginx (fullchain.pem)
* Monitor expiry with Uptime Kuma or a calendar alert

A syntax error in Nginx takes down every site on the same reload. Always run nginx -t before systemctl reload nginx.

### When to move up a plan

Dozens of certificates and heavy TLS traffic can demand more CPU. Corporate sites fit a [Xeon VPS](https://streethosting.com.br/en/vps/xeon); apps with heavy encryption next to a game server fit a [Ryzen VPS](https://streethosting.com.br/en/vps/ryzen). Critical multi-tenant projects can move to a [dedicated server](https://streethosting.com.br/en/dedicated). Minecraft communities with a managed web panel use [Minecraft Pro](https://streethosting.com.br/en/minecraft-pro) with SSL already included in the panel flow.

In this guide

* [What SSL is and why it matters](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#o-que-e-ssl)
* [VPS prerequisites](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#pre-requisitos)
* [Install Certbot and Nginx](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#instalar-certbot)
* [Multiple domains and renewal](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#varios-dominios)
* [Troubleshooting and auditing](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps#troubleshooting)

## Frequently asked questions

Is Let's Encrypt free forever?

Yes, for validated domains. Rate limits exist: plan batch issuance carefully.

Does it work with a bare IP?

No. You need a domain pointing to the VPS IP through an A record or a CNAME.

Does it renew on its own?

Yes, as long as the systemd timer or cron job is active. Test it monthly with certbot renew --dry-run.

Wildcard on a VPS?

Yes, through the DNS challenge. It needs a plugin or a manual script at your DNS provider. On a VPS, a per-domain certificate with the Nginx plugin is more common.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Xeon VPS Xeon VPS for steady workloads, automation and long-running projects.](https://streethosting.com.br/en/vps/xeon) [See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen)

## Related guides

[VPS Intermediate How to host multiple websites on one VPS with Nginx A well-configured VPS can carry several small projects. The trick is separate server blocks, a default server that rejects unknown domains, one Linux user and one PHP pool per site, and independent certificates. 9 min Read guide](https://streethosting.com.br/en/guides/vps/multiple-websites-on-one-vps) [VPS Intermediate How to secure SSH on a Linux VPS: keys, passwords, fail2ban SSH is usually the first target on any VPS with a public IP. This guide walks through a practical routine that cuts the risk without complicating your day: an ED25519 key, password-free login, admin access through sudo, blocking of automated attempts and a periodic review of authorized keys. 4 min Read guide](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps) [VPS Beginner UFW on Ubuntu VPS: firewall rules without losing SSH UFW makes the Ubuntu firewall simpler, but one rule in the wrong order locks you out of your VPS. Learn how to enable it without losing SSH, open only what you need, deal with Docker, and get back in through the console if something goes wrong. 10 min Read guide](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
