Como instalar un certificado SSL con Let's Encrypt en Ubuntu 18.04 con Apache

Como instalar un certificado SSL con Let's Encrypt en Ubuntu 18.04 con Apache

 Paso 1 - Instalar Cerbot

sudo add-apt-repository ppa:certbot/certbot
sudo apt install python-certbot-apache

Paso 2 - Configurar el certificado SSL

sudo certbot --apache -d domain.tld -d www.domain.tld

Una vez ejecutado el commando nos preguntará como queremos configurar el virtualhost.

Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
-------------------------------------------------------------------------------
1: No redirect - Make no further changes to the webserver configuration.
2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for
new sites, or if you're confident your site works on HTTPS. You can undo this
change by editing your web server's configuration.
-------------------------------------------------------------------------------
Select the appropriate number [1-2] then [enter] (press 'c' to cancel):

Una vez seleccionada la opcion que más te interesa, nos mostrará una salida similiar a esta:


Output
IMPORTANT NOTES:
 - Congratulations! Your certificate and chain have been saved at:
   /etc/letsencrypt/live/**your_domain**/fullchain.pem
   Your key file has been saved at:
   /etc/letsencrypt/live/**your_domain**/privkey.pem
   Your cert will expire on 2018-07-23. To obtain a new or tweaked
   version of this certificate in the future, simply run certbot again
   with the "certonly" option. To non-interactively renew *all* of
   your certificates, run "certbot renew"
 - Your account credentials have been saved in your Certbot
   configuration directory at /etc/letsencrypt. You should make a
   secure backup of this folder now. This configuration directory will
   also contain certificates and private keys obtained by Certbot so
   making regular backups of this folder is ideal.
 - If you like Certbot, please consider supporting our work by:

   Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
   Donating to EFF:                    https://eff.org/donate-le

Tu certificado se ha generado y guardado en los siguientes ficheros:

  • /etc/letsencrypt/live/your_domain/fullchain.pem
  • /etc/letsencrypt/live/your_domain/privkey.pem

Ahora deberias tener un nuevo virtualhost configurado con https y con los certificados, si no es así abre tu viertualhost y añadde estas lineas:

Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/**your_domain**/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/**your_domain**/privkey.pem