Generate the Certbot command to get a certificate, plus the resulting Nginx or Apache SSL config — HSTS, OCSP stapling, and session settings included.
Every directive this tool generates has been checked against real Nginx and Apache binaries, not just read over for typos — including some genuinely obscure scope rules (like SSLStaplingCache being illegal inside a <VirtualHost> block, and needing a different cache syntax than Nginx entirely) that only a real server actually catches.
Certbot sets up automatic renewal on its own (a systemd timer or cron job, depending on your OS) — verify it's active with systemctl list-timers | grep certbot, and test that renewal actually works without waiting for expiry using certbot renew --dry-run. A cert that fails to silently auto-renew is one of the most common ways sites go down. See How to use ProxyForge for a walkthrough of every setting and where the output goes.
Pick Nginx or Apache, then choose how Certbot will obtain the cert — automatic, webroot, or standalone.
Enter your domain(s) and email, toggle wildcard, HSTS, or OCSP stapling as needed — both outputs update live.
Run the Certbot command to get the certificate, then copy the SSL config into your existing server block.
ssl-config.mozilla.org now redirects). Rather than bake a cipher list in here and risk it going stale, get the current ssl_ciphers line from TLS Configurator (choose Intermediate, unless you specifically know you want Modern) and drop it into the config below.
Let's Encrypt (what Certbot uses) only issues free domain-validated certs. For EV/OV certificates, or a wildcard cert without DNS API access, you'd need a paid CA instead:
Some links above are affiliate links — signing up through them may earn this site a small commission at no extra cost to you. See the privacy policy for details.