SSL / Let's Encrypt Generator

Generate the Certbot command to get a certificate, plus the resulting Nginx or Apache SSL config — HSTS, OCSP stapling, and session settings included.

About this tool

Every directive this tool generates has been checked against real Nginx and Apache binaries, not just read over for typos — including some genuinely obscure scope rules (like SSLStaplingCache being illegal inside a <VirtualHost> block, and needing a different cache syntax than Nginx entirely) that only a real server actually catches.

Certbot sets up automatic renewal on its own (a systemd timer or cron job, depending on your OS) — verify it's active with systemctl list-timers | grep certbot, and test that renewal actually works without waiting for expiry using certbot renew --dry-run. A cert that fails to silently auto-renew is one of the most common ways sites go down. See How to use ProxyForge for a walkthrough of every setting and where the output goes.

How it works

STEP 1

Pick Nginx or Apache, then choose how Certbot will obtain the cert — automatic, webroot, or standalone.

STEP 2

Enter your domain(s) and email, toggle wildcard, HSTS, or OCSP stapling as needed — both outputs update live.

STEP 3

Run the Certbot command to get the certificate, then copy the SSL config into your existing server block.

Must match the document root your web server already serves this domain from.
Comma-separated for multiple domains on one certificate.
Requires a DNS-01 challenge — Certbot can't prove domain ownership over HTTP for a wildcard.
Only used by Let's Encrypt for renewal and expiry notices.
Tells browsers to always use HTTPS for this domain from now on.
Server proves the cert isn't revoked, instead of every visitor's browser checking separately.
STEP 1 — RUN THIS TO GET THE CERTIFICATE
nginx-ssl.conf ✓ Verified: Nginx 1.27.x
About cipher suites: this deliberately doesn't hardcode a cipher list. The underlying guidelines changed materially this year — an entire category of ciphers was dropped from the Intermediate profile, and the old "legacy" compatibility profile was removed outright as no longer recommended. Mozilla has since stepped back from actively maintaining its own generator (the project moved to community maintenance as TLS Configurator, which is where ssl-config.mozilla.org now redirects). Rather than bake a cipher list in here and risk it going stale, get the current ssl_ciphers line from TLS Configurator (choose Intermediate, unless you specifically know you want Modern) and drop it into the config below.

Need something Certbot can't give you?

Let's Encrypt (what Certbot uses) only issues free domain-validated certs. For EV/OV certificates, or a wildcard cert without DNS API access, you'd need a paid CA instead:

SSL.com EV, OV, and wildcard certificates with manual domain validation. Get started
UptimeRobot Free uptime monitoring, plus SSL expiry alerts on paid plans — know before a renewal silently fails. Get started
Vultr Simple cloud servers with a wide range of data center locations. Get started

Some links above are affiliate links — signing up through them may earn this site a small commission at no extra cost to you. See the privacy policy for details.