1.SSL Certificate Acquisition ( Let's Encrypt )
1.1 advance preparation
1.Package management system Snappy installation
Since the SSL certificate issuing tool "certbot" of Let's Encrypt is recommended to be installed using "snap" after 2021, install Snapd first.(Can also be installed the traditional way with dnf or yum)
# dnf -y install snapd
Enable systemd unit to manage the main snap communication socket
# systemctl enable --now snapd.socket
Enable Classics Snap support
# ln -s /var/lib/snapd/snap /snap
Version Confirmation
# snap --version
snap 2.76-0.el10_3
snapd 2.76-0.el10_3
series 16
ol 10.2
kernel 6.12.0-204.92.4.3.el10uek.x86_64
architecture amd64
Log out and log in again or reboot the system to ensure that the snap path is updated correctly
2.certbot package installation
# snap install --classic certbot
certbot 5.7.0 from Certbot Project (certbot-eff✓) installed
Create symbolic link to /snap/bin/certbot
# ln -s /snap/bin/certbot /usr/bin/certbot
Confirmation
# ls -la /usr/bin/certbot
lrwxrwxrwx 1 root root 17 Nov 30 12:29 /usr/bin/certbot -> /snap/bin/certbot
# ls -la /snap/bin/certbot
lrwxrwxrwx 1 root root 13 Nov 30 12:29 /snap/bin/certbot -> /usr/bin/snap
1.2 Obtaining Certificates
# certbot certonly --webroot -w /var/www/html/[FQDN] -d [FQDN]
Registration of e-mail address and agreement to terms of use are required for the first time only.
Specify an email address to receive
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Enter email address or hit Enter to skip.
(Enter 'c' to cancel): [mail address]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Please read the Terms of Service at:
https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf
You must agree in order to register with the ACME server. Do you agree?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(Y)es/(N)o: y
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Would you be willing, once your first certificate is successfully issued, to
share your email address with the Electronic Frontier Foundation, a founding
partner of the Let's Encrypt project and the non-profit organization that
develops Certbot? We'd like to send you email about our work encrypting the web,
EFF news, campaigns, and ways to support digital freedom.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(Y)es/(N)o: y
Account registered.
Requesting a certificate for [FQDN]
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/[FQDN]/fullchain.pem
Key is saved at: /etc/letsencrypt/live/[FQDN]/privkey.pem
This certificate expires on 2026-10-15.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
If you like Certbot, please consider supporting our work by:
* Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate
* Donating to EFF: https://eff.org/donate-le
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
The following certificate is obtained under [/etc/letsencrypt/live/[FQDN]/] as described in the message
cert.pem ⇒ SSL server certificate (including public key)
chain.pem ⇒ intermediate certificate
fullchain.pem ⇒ File containing cert.pem and chain.pem combined
privkey.pem ⇒ private key for a public key
※Obtaining a Let's Encrypt certificate when the web server is not running
It is a prerequisite that the server on which the work is to be performed is accessible from the Internet at port 80.
Use the simple Web server function by specifying [--standalone].
# certbot certonly --standalone -d [FQDN]
Renewing certificates already obtained
# Renew all certificates with an expiration date of less than 30 days
# If you want to renew regardless of the number of days remaining on the expiration date, specify [--force-renewal] as well
# certbot [--force-renewal] renew
1.2 Automatic renewal of certificates (Let's Encrypt)
①Pre-registration testing
First, test the automatic update using the following --dry-run option.
With this option, certificates are not renewed, only checked, so there is no need to worry about getting stuck with a limit on the number of times a certificate can be obtained.
# certbot renew --dry-run
Saving debug log to /var/log/letsencrypt/letsencrypt.log
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/[FQDN].conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Account registered.
Simulating renewal of an existing certificate for [FQDN]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations, all simulated renewals succeeded:
/etc/letsencrypt/live/[FQDN]/fullchain.pem (success)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
②When you install the snap version of certbot, the automatic certificate renewal function is also installed.
# systemctl list-timers | less
NEXT LEFT LAST PASSED UNIT ACTIVATES
Fri 2026-07-17 16:40:00 JST 3min 54s Fri 2026-07-17 16:30:02 JST 6min ago sysstat-collect.timer sysstat-collect.service
Fri 2026-07-17 16:50:00 JST 13min Fri 2026-07-17 16:20:00 JST 16min ago pmlogger_check.timer pmlogger_check.service
Fri 2026-07-17 16:50:10 JST 14min Fri 2026-07-17 16:20:11 JST 15min ago pmlogger_farm_check.timer pmlogger_farm_check.service
Fri 2026-07-17 16:58:00 JST 21min Fri 2026-07-17 16:28:02 JST 8min ago pmie_check.timer pmie_check.service
Fri 2026-07-17 16:58:10 JST 22min Fri 2026-07-17 16:28:12 JST 7min ago pmie_farm_check.timer pmie_farm_check.service
Fri 2026-07-17 17:14:39 JST 38min Fri 2026-07-17 16:06:18 JST 29min ago dnf-makecache.timer dnf-makecache.service
Fri 2026-07-17 17:18:51 JST 42min Fri 2026-07-17 16:20:07 JST 15min ago fwupd-refresh.timer fwupd-refresh.service
Fri 2026-07-17 21:38:00 JST 5h 1min - - snap.certbot.renew.timer snap.certbot.renew.service
Sat 2026-07-18 00:00:00 JST 7h - - sa-update.timer sa-update.service
Sat 2026-07-18 00:00:00 JST 7h - - sysstat-rotate.timer sysstat-rotate.service
Sat 2026-07-18 00:00:00 JST 7h Fri 2026-07-17 08:39:26 JST 7h ago unbound-anchor.timer unbound-anchor.service
Sat 2026-07-18 00:00:29 JST 7h Fri 2026-07-17 09:27:16 JST 7h ago logrotate.timer logrotate.service
Sat 2026-07-18 00:07:00 JST 7h - - sysstat-summary.timer sysstat-summary.service
Sat 2026-07-18 00:08:00 JST 7h Fri 2026-07-17 08:39:38 JST 7h ago pmie_daily.timer pmie_daily.service
Sat 2026-07-18 00:10:00 JST 7h Fri 2026-07-17 08:39:39 JST 7h ago pmlogger_daily.timer pmlogger_daily.service
Sat 2026-07-18 00:26:39 JST 7h Fri 2026-07-17 09:07:06 JST 7h ago plocate-updatedb.timer plocate-updatedb.service
Sat 2026-07-18 08:54:26 JST 16h Fri 2026-07-17 08:54:26 JST 7h ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
Sun 2026-07-19 01:00:00 JST 1 day 8h Thu 2026-07-16 10:29:45 JST - raid-check.timer raid-check.service
Mon 2026-07-20 00:03:49 JST 2 days Thu 2026-07-16 10:29:45 JST - fstrim.timer fstrim.service
snap.certbot.renew.timer is registered
Check the unit file snap.certbot.renew.timer
# vi /etc/systemd/system/snap.certbot.renew.timer
[Unit]
# Auto-generated, DO NOT EDIT
Description=Timer renew for snap application certbot.renew
Requires=var-lib-snapd-snap-certbot-5758.mount
After=var-lib-snapd-snap-certbot-5758.mount
X-Snappy=yes
[Timer]
Unit=snap.certbot.renew.service
OnCalendar=*-*-* 10:31
OnCalendar=*-*-* 21:38
[Install]
WantedBy=timers.target
According to the above configuration, it will attempt to update at 10:31 and 21:38 every day as specified in the OnCalender parameter(However, the set time changes randomly with each update)
Check the unit file snap.certbot.renew.service
# vi /etc/systemd/system/snap.certbot.renew.service
[Unit]
# Auto-generated, DO NOT EDIT
Description=Service for snap application certbot.renew
Requires=var-lib-snapd-snap-certbot-5758.mount
Wants=network.target
After=var-lib-snapd-snap-certbot-5758.mount network.target snapd.apparmor.service
X-Snappy=yes
[Service]
EnvironmentFile=-/etc/environment
ExecStart=/usr/bin/snap run --timer="00:00~24:00/2" certbot.renew
SyslogIdentifier=certbot.renew
Restart=no
WorkingDirectory=/var/snap/certbot/5758
TimeoutStopSec=30s
Type=oneshot
However, the web server using the certificate will not be restarted, so set up a script that will run automatically after the update
# vi /etc/letsencrypt/renewal-hooks/post/web_restart.sh
Describe the following
#!/bin/bash
systemctl reload httpd
# chmod 755 /etc/letsencrypt/renewal-hooks/post/web_restart.sh
2. Converting Apache to https
Install the following
# dnf -y install mod_ssl
2.1 Edit ssl.conf file
# vi /etc/httpd/conf.d/ssl.conf
Line 43; Uncomment and change
DocumentRoot "/var/www/html/[FQDN]"
Line 44; Uncomment and change
ServerName [FQDN]:443
Line 85; make it a comment and add below it
# SSLCertificateFile /etc/pki/tls/certs/localhost.crt
SSLCertificateFile /etc/letsencrypt/live/[FQDN]/cert.pem
Line 93; make a comment and add below it
# SSLCertificateKeyFile /etc/pki/tls/private/localhost.key
SSLCertificateKeyFile /etc/letsencrypt/live/[FQDN]/privkey.pem
Line 103; Add.
SSLCertificateChainFile /etc/letsencrypt/live/[FQDN]/chain.pem
Restart Apache.
# systemctl restart httpd
Allow https in Firewall
# firewall-cmd --add-service=https --permanent
# firewall-cmd --reload
2.2 Redirect HTTP communications to HTTPS
Add to the virtual host configuration file
# vi /etc/httpd/conf.d/vhost.conf
<VirtualHost *:80>
RewriteEngine On ←Add
RewriteCond %{HTTPS} off ←Add
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L] ←Add
DocumentRoot /var/www/html/[FQDN]
ServerName [FQDN]
ServerAdmin [email address]
ErrorLog logs/[FQDN].error_log
CustomLog logs/[FQDN].access_log combined
</VirtualHost>
<Directory "/var/www/html/[FQDN]">
Options FollowSymLinks
AllowOverride All
</Directory>
Apache restart
# systemctl restart httpd
3. SSL/TLS (Let's Encrypt) settings on the mail server
3.1 Obtaining a certificate for the mail server
Obtain a certificate for the mail server, but it cannot be obtained in the same way as above, so the following with the "--standalone" option fails.
# systemctl stop httpd.service
# certbot certonly --standalone -d mail.[domain name]
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for mail.korodes.com
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/mail.[Domain]/fullchain.pem
Key is saved at: /etc/letsencrypt/live/mail.[Domain]/privkey.pem
This certificate expires on 2026-10-15.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
If you like Certbot, please consider supporting our work by:
* Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate
* Donating to EFF: https://eff.org/donate-le
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
# systemctl start httpd
3.2 Postfix Configuration
# vi /etc/postfix/main.cf
Per Line 718, 724 : commenting
#smtpd_tls_cert_file = /etc/pki/tls/certs/postfix.pem
#smtpd_tls_key_file = /etc/pki/tls/private/postfix.key
Add to the last line
smtpd_use_tls = yes
smtp_tls_mandatory_protocols = !SSLv2, !SSLv3
smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.[Domain]/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.[Domain]/privkey.pem
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
# vi /etc/postfix/master.cf
Line 19-22 : Uncomment
submission inet n - n - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
Line 38-41 : Uncomment
submissions inet n - n - - smtpd
-o syslog_name=postfix/smtps
-o smtpd_tls_wrappermode=yes
-o smtpd_sasl_auth_enable=yes
3.3 Dovecot Settings
# vi /etc/dovecot/conf.d/10-ssl.conf
Line 9: Confirmation
ssl = yes
Lines 14 and 15: Comment and add certificate/key file designation below
#ssl_cert = </etc/pki/dovecot/certs/dovecot.pem
#ssl_key = </etc/pki/dovecot/private/dovecot.pem
ssl_cert = </etc/letsencrypt/live/mail.[Domain]/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.[Domain]/privkey.pem
Allow Port 587 in firewall
Restart Postfix and Dovecot
# firewall-cmd --add-port=587/tcp --permanent
# firewall-cmd --reload
# systemctl restart postfix dovecot
3.4 Thunderbird Settings
Receiving server
Port : 143
Connection security : STARTTLS
Authentication method : Normal password

Sending server
Port : 587
Connection security : STARTTLS
Authentication method : Normal password

