Certbot
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- Linux, Mac, self-hosted, Windows

Summary
Certbot is free, open-source software that helps administrators enable HTTPS on websites they manage manually. It can obtain Let’s Encrypt certificates and install them on a web server automatically in many cases, then renew certificates when less than one-third of their lifetime remains. For certificates lasting 10 days or less, renewal happens when half their lifetime remains. The project names Apache and Nginx integrations, as well as webroot and standalone methods. DNS validation is another option and does not require an inbound connection from Let’s Encrypt, so that method does not depend on an existing HTTP site or open port 80. Certbot runs from a command line, usually on a Unix-like server; many users connect to a remote server over SSH. It is made by the Electronic Frontier Foundation. Project documentation and the Let’s Encrypt community forum are listed as support resources.
Who it is for
Certbot may suit people comfortable with command-line work who administer websites on dedicated servers, VPSs, or cloud-hosted servers. It is less suited to most shared hosting environments, where asking the hosting provider to configure HTTPS is usually easier and more reliable.
What is good
- Free and open-source software.
- Can obtain and install Let’s Encrypt certificates automatically.
- Renews certificates automatically.
- Includes Apache and Nginx integrations.
- DNS validation avoids requiring an inbound server connection.
What to know first
- Runs through a command-line interface.
- Less suitable for most shared hosting environments.
Everything Xiaomi review
Certbot: the full review
Certbot is aimed at administrators managing their own web servers and wanting to automate HTTPS certificates and renewal. Shared hosting users may find provider-managed HTTPS more suitable.
Overview
Certbot is free, open-source software from the Electronic Frontier Foundation for automating Let’s Encrypt certificates on websites you administer. Its command-line approach makes it a practical fit for server administrators who want HTTPS certificate setup and renewal handled alongside their web server. The trade-off is that it expects access to the server itself, making it a poor match for most shared hosting.
Key features
Certbot can obtain a certificate from a certificate authority and install it on a web server automatically in many cases. It supports Apache and Nginx integrations, plus webroot and standalone methods. That gives administrators several ways to handle certificate setup, but the command-line workflow still assumes comfort managing the server.
Automatic renewal runs when less than one-third of a certificate’s lifetime remains, or when half remains for certificates lasting 10 days or less. That reduces the need to track renewal dates manually. Deployment automation and revocation workflows are supported; certificate discovery is not, so Certbot is focused on obtaining and managing certificates rather than finding them across an environment.
DNS validation does not require Let’s Encrypt to make an inbound connection to the server. As a result, this method does not require an existing HTTP site or an open port 80, which can help where those conditions are unavailable. Certbot usually runs on a Unix-like server, and most users access it remotely over SSH.
Pricing
Certbot costs 0.00 USD per free. The free plan includes the open-source software and its Let’s Encrypt certificate automation, with no free trial because there is no paid plan to evaluate. That makes it a straightforward choice for administrators seeking certificate automation without a software fee; the cost is the server access and command-line administration the workflow requires.
Platforms
Certbot is listed for Linux, macOS, self-hosted environments, and Windows. Its typical workflow is on a Unix-like server, often reached over SSH, so the platform list does not change its basic requirement: users need to administer the web server where certificates are installed.
Who it's for
Certbot suits people comfortable with the command line who run a website on a dedicated server, VPS, or cloud-hosted server. It is most compelling when they want certificate installation and renewal automated without paying for software. For most shared hosting users, asking the hosting provider to configure HTTPS is usually easier and more reliable.
Pros and cons
Pros
- Free and open source: Certificate automation comes without a software charge, making it accessible to administrators on any budget.
- Automated renewal: Renewing based on remaining certificate lifetime reduces manual date tracking.
- Multiple setup methods: Apache, Nginx, webroot, standalone, and DNS validation give administrators options for different server circumstances.
- DNS validation flexibility: It can work without an existing HTTP site or open port 80.
Cons
- Requires server administration: The command-line workflow is a hurdle for users who cannot manage their own server.
- Weak fit for shared hosting: Provider-managed HTTPS is generally easier and more reliable in that environment.
- No certificate discovery: Certbot does not provide this capability, limiting its role in environments that need to locate certificates across systems.
Alternatives
Certificate Management Software is a useful category page for comparing other tools in this area.
- Certify The Web is worth considering if its free evaluation or freemium model better fits your selection process; it supports a wider range of listed platforms, including API and web.
- Qualys External Attack Surface Management may suit users who want to try a freemium product with a 30-day no-cost plan, rather than Certbot’s free, open-source server workflow.
- Oracle Cloud Infrastructure Secret Management is an alternative for readers seeking a free secrets-management product with API and web platforms.
- AWS Certificate Manager offers a free public-certificate plan for integrated AWS services; choose it if that AWS-specific scope fits better than managing certificates through Certbot.
- KeyTalk CKMS is a paid option with a trial and support for mobile, desktop, Linux, and self-hosted platforms.
- Entrust Certificate Manager is a paid alternative for readers considering a commercial certificate management product.
- ManageEngine Key Manager Plus is a freemium alternative with a trial and an on-premises license for 25 managed keys at 59.00 USD per month.
- Keyfactor Platform is a paid option with a trial for readers considering certificate lifecycle automation.
Verdict
Choose Certbot if you administer your own server and want free, open-source automation for obtaining, installing, and renewing Let’s Encrypt certificates. Its renewal automation and multiple validation methods are useful strengths. Look elsewhere if you rely on shared hosting or need certificate discovery; provider-managed HTTPS is the more suitable route for most shared hosting users.
Certbot plans and pricing
All plansCompared on certificate management software
- Free plan
- Yescertbot.eff.org
- Certificate discovery
- Nocertbot.eff.org
- Automatic renewal
- Yescertbot.eff.org
- Deployment automation
- Yescertbot.eff.org
- Revocation workflows
- Yescertbot.eff.org
- Certificate types
- tlscertbot.eff.org
- CA integrations
- Yescertbot.eff.org
Facts
- Purpose
- Certbot automatically uses Let’s Encrypt certificates on manually administered websites to enable HTTPS.certbot.eff.org · 3 Oct 2026
- Open source
- Certbot is free, open source software.certbot.eff.org · 3 Oct 2026
- Certificate renewal
- Certbot renews certificates when less than one-third of their lifetime remains, or half their lifetime for certificates lasting 10 days or less.certbot.eff.org · 3 Oct 2026
- Web server integration
- The site names Apache and Nginx integrations and also describes webroot and standalone usage methods.certbot.eff.org · 3 Oct 2026
- DNS validation
- DNS validation does not require Let’s Encrypt to make an inbound connection to the server, so an existing HTTP site or open port 80 is not required for this method.certbot.eff.org · 3 Oct 2026
- Command line
- Certbot runs from a command-line interface, usually on a Unix-like server, and most users run it on a remote server over SSH.certbot.eff.org · 3 Oct 2026
- Intended users
- Certbot may suit people comfortable with the command line who administer a website on a dedicated server, VPS, or cloud-hosted server.certbot.eff.org · 3 Oct 2026
- Shared hosting limitation
- Certbot is less suitable for most shared hosting environments, where asking the provider to set up HTTPS is usually easier and more reliable.certbot.eff.org · 3 Oct 2026
- HTTPS automation
- Certbot can help obtain a certificate from a certificate authority and install it onto a web server automatically in many cases.certbot.eff.org · 3 Oct 2026
- Support
- The site points users to project documentation and the Let’s Encrypt community forum for help.certbot.eff.org · 3 Oct 2026
- Security purpose
- The project says it aims to help make the internet more structurally private, safe, and protected against censorship through HTTPS adoption.certbot.eff.org · 3 Oct 2026
- Maker
- Certbot is made by the Electronic Frontier Foundation, which the site describes as a 501(c)(3) nonprofit based in San Francisco, California.certbot.eff.org · 3 Oct 2026
Company
- Headquarters
- San Francisco, California, United Statescertbot.eff.org · 28 Sept 2026
Best Certbot alternatives
See all 20Where it ranks on Everything Xiaomi
Is Certbot yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- certbot.eff.org/pages/about· checked 3 Oct 2026
- certbot.eff.org/hosting_providers· checked 3 Oct 2026
- certbot.eff.org/pages/help· checked 3 Oct 2026
- certbot.eff.org· checked 28 Sept 2026



