{"id":25,"date":"2026-08-22T21:53:53","date_gmt":"2026-08-23T04:53:53","guid":{"rendered":"https:\/\/pointyhair.com\/?p=25"},"modified":"2026-08-22T21:53:53","modified_gmt":"2026-08-23T04:53:53","slug":"letsencrypt-free-real-ssl-certificates","status":"publish","type":"post","link":"https:\/\/pointyhair.com\/index.php\/2026\/08\/22\/letsencrypt-free-real-ssl-certificates\/","title":{"rendered":"LetsEncrypt free REAL SSL certificates"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The days of paying $250\/year for a certificate are over. The Urge to build your own self-signed certificate (that only works for your own browser) are gone. Trying to work without a certificate, and having every browser flag your site as bad&#8230;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Enter Let&#8217;s Encrypt &#8212; First thing you need to down load <strong>certbot<\/strong> from <a href=\"https:\/\/letsencrypt.org\/\">https:\/\/letsencrypt.org\/<\/a> Simplest way is to say that you&#8217;re running your own (Linux) server and you&#8217;re running Apache web server. Once you have Apache set to serve your domain(s) using regular HTTP (port 80), you just need to run <code>certbot --apache<\/code> or <code>certbot --apache certonly<\/code> Assuming your DNS ios set up correctly, and your apache is open, this should ytield you certificates that are valid. You can safely use the <strong>ECDSA<\/strong> type certificates (as opposed to older <strong>RSA<\/strong> type certificates), as one certificate will server multiple domains.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now if you have all your ECDSA certificates in one certificate and you want all your site certificates to be refreshed at as they age, you need to add them to<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The days of paying $250\/year for a certificate are over. The Urge to build your own self-signed certificate (that only works for your own browser) are gone. Trying to work without a certificate, and having every browser flag your site as bad&#8230; Enter Let&#8217;s Encrypt &#8212; First thing you need to down load certbot from&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"slim_seo":{"title":"LetsEncrypt free REAL SSL certificates - Pointyhair","description":"The days of paying $250\/year for a certificate are over. The Urge to build your own self-signed certificate (that only works for your own browser) are gone. Try"},"footnotes":""},"categories":[1],"tags":[],"class_list":["post-25","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/posts\/25","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/comments?post=25"}],"version-history":[{"count":4,"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/posts\/25\/revisions"}],"predecessor-version":[{"id":162,"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/posts\/25\/revisions\/162"}],"wp:attachment":[{"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/media?parent=25"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/categories?post=25"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pointyhair.com\/index.php\/wp-json\/wp\/v2\/tags?post=25"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}