This is an update from my earlier post on the same subject for more than a year ago. The SSL certification is the same but the process has changed.
Getting free SSL certificates from Let's Encrypt is a multi steps process. Sites like SSL for Free and ZeroSSL make it simpler.
However, they want to verify that you have the control over the domain where the free SSL certificate is for. They want you to create TXT records in the DNS server that hosts your domain. They will give the details of the TXT records for you to enter. Then they will query the DNS server for the TXT records. If the records are the same then you are verified to have the control over the domain, and they will create the certificate for you.
They just create the certificate. You have to install it in your hosting server.
I was getting the free SSL certificate for my https://cryptobubbles.club from Let's Encrypt. In fact I wanted to have HTTPS for https://answering.cryptobubbles.club because I wanted to test my new plugin that utilizes the Waves crypto payment gateway. The latter is a question and answer site. If you like someone's question or answer then you can donate points to him. You pay for the points in Waves based tokens.
Take a look at my Waves based tokens Jualla and Blindtalk. The sites are here and here.
In my earlier post I was using the service of SSL for Free. Now I am using the ZeroSSL service.
DNS Verification and Certificate Creation
Installing the Free SSL Certificate
Done. This process will have to be repeated for every 90 days which is the validity period of the Let's Encrypt certificate. I'm still hoping that GoDaddy will simplify the process, or make it automatic.
Getting free SSL certificates from Let's Encrypt is a multi steps process. Sites like SSL for Free and ZeroSSL make it simpler.
However, they want to verify that you have the control over the domain where the free SSL certificate is for. They want you to create TXT records in the DNS server that hosts your domain. They will give the details of the TXT records for you to enter. Then they will query the DNS server for the TXT records. If the records are the same then you are verified to have the control over the domain, and they will create the certificate for you.
They just create the certificate. You have to install it in your hosting server.
I was getting the free SSL certificate for my https://cryptobubbles.club from Let's Encrypt. In fact I wanted to have HTTPS for https://answering.cryptobubbles.club because I wanted to test my new plugin that utilizes the Waves crypto payment gateway. The latter is a question and answer site. If you like someone's question or answer then you can donate points to him. You pay for the points in Waves based tokens.
Take a look at my Waves based tokens Jualla and Blindtalk. The sites are here and here.
In my earlier post I was using the service of SSL for Free. Now I am using the ZeroSSL service.
DNS Verification and Certificate Creation
- In GoDaddy web hosting manager, open the cPanel Admin. Click Security->SSL/TLS. And then click "Generate, view, or delete SSL certificate signing requests."
- In the Domains box enter your domain.
- Enter all other required fields such as your company name and address.
- Click Generate.
- Copy the Encoded Certificate Signing Request (CSR).
- In ZeroSSL click Online Tools. And click Start. Paste the CSR in the respective box.
- Select Accept ZeroSSL TOS and Accept Let's Encrypt SA. Click Next.
- The Account Key is generated. Copy the Account Key. Click Next.
- The verification TXT records are shown.
- In GoDaddy cPanel, open the DNS Manager. And select DNS->Manage Zones.
- Enter your domain name. The DNS records for your domain will be listed. At the end of the record list click the Add button.
- In the Type field select TXT.
- In the Host field enter the detail given by ZeroSSL. It coud be _acme-challenge. You must not include your domain name in the Host field. In my case I got _acme-challenge.cryptobubbles.club and entered as is, and the verification failed.
- In the TXT Value field enter the detail given by ZeroSSL.
- In the TTL field enter the shortest period. Select Custom and enter 600 seconds which is 10 minutes.
- Click Save and repeat for the other TXT record.
- Wait for at least 10 minutes because we set the TTL to be that long.
- In ZeroSSL, click Next.
- ZeroSSL will show "Your certificate is ready!" with some messages.
- Copy the certificate. Click Done Next.
Installing the Free SSL Certificate
- In the GoDaddy cPanel, click Security->SSL/TLS. Then, click "Generate, view, upload, or delete SSL certificates."
- Paste the certificate into the Upload a New Certificate box.
- Click the Save Certificate button.
- The certificate has been saved. Click Go Back.
- Find your domain in the certificate list. Click Install.
- The certificate details are populated in a number of fields.
- Click Install Certificate.
Done. This process will have to be repeated for every 90 days which is the validity period of the Let's Encrypt certificate. I'm still hoping that GoDaddy will simplify the process, or make it automatic.
Good step-by-step instructions and they do work as stated (March 2020). But note the issue at step 13, it is important.ZeroSSL instructions are not correct. Neither can you use nslookup to confirm visibility. nslookup will fail with an NXDOMAIN error. After you create the TXT records, simply wait 15 minutes then click NEXT on ZeroSSL. HTH...
ReplyDeleteThe content is utmost interesting! I have completely enjoyed reading your points and have come to the conclusion that you are right about many of them. You are great, and your efforts are outstanding! CE certificate
ReplyDelete