Certbot

B
B tier on Certificate Management SoftwareScore 7.1 · #2 of 31
Android app
Not listed
Free plan
Yes
Runs on
Linux, Mac, self-hosted, Windows
certbot.eff.org
The Certbot homepage

Summary

Certbot is free, open-source software that helps administrators enable HTTPS on websites they manage manually. It can obtain Let’s Encrypt certificates and install them on a web server automatically in many cases, then renew certificates when less than one-third of their lifetime remains. For certificates lasting 10 days or less, renewal happens when half their lifetime remains. The project names Apache and Nginx integrations, as well as webroot and standalone methods. DNS validation is another option and does not require an inbound connection from Let’s Encrypt, so that method does not depend on an existing HTTP site or open port 80. Certbot runs from a command line, usually on a Unix-like server; many users connect to a remote server over SSH. It is made by the Electronic Frontier Foundation. Project documentation and the Let’s Encrypt community forum are listed as support resources.

Who it is for

Certbot may suit people comfortable with command-line work who administer websites on dedicated servers, VPSs, or cloud-hosted servers. It is less suited to most shared hosting environments, where asking the hosting provider to configure HTTPS is usually easier and more reliable.

What is good

  • Free and open-source software.
  • Can obtain and install Let’s Encrypt certificates automatically.
  • Renews certificates automatically.
  • Includes Apache and Nginx integrations.
  • DNS validation avoids requiring an inbound server connection.

What to know first

  • Runs through a command-line interface.
  • Less suitable for most shared hosting environments.

Everything Xiaomi review

Certbot: the full review

Certbot is aimed at administrators managing their own web servers and wanting to automate HTTPS certificates and renewal. Shared hosting users may find provider-managed HTTPS more suitable.

Overview

Certbot is free, open-source software from the Electronic Frontier Foundation for automating Let’s Encrypt certificates on websites you administer. Its command-line approach makes it a practical fit for server administrators who want HTTPS certificate setup and renewal handled alongside their web server. The trade-off is that it expects access to the server itself, making it a poor match for most shared hosting.

Key features

Certbot can obtain a certificate from a certificate authority and install it on a web server automatically in many cases. It supports Apache and Nginx integrations, plus webroot and standalone methods. That gives administrators several ways to handle certificate setup, but the command-line workflow still assumes comfort managing the server.

Automatic renewal runs when less than one-third of a certificate’s lifetime remains, or when half remains for certificates lasting 10 days or less. That reduces the need to track renewal dates manually. Deployment automation and revocation workflows are supported; certificate discovery is not, so Certbot is focused on obtaining and managing certificates rather than finding them across an environment.

DNS validation does not require Let’s Encrypt to make an inbound connection to the server. As a result, this method does not require an existing HTTP site or an open port 80, which can help where those conditions are unavailable. Certbot usually runs on a Unix-like server, and most users access it remotely over SSH.

Pricing

Certbot costs 0.00 USD per free. The free plan includes the open-source software and its Let’s Encrypt certificate automation, with no free trial because there is no paid plan to evaluate. That makes it a straightforward choice for administrators seeking certificate automation without a software fee; the cost is the server access and command-line administration the workflow requires.

Platforms

Certbot is listed for Linux, macOS, self-hosted environments, and Windows. Its typical workflow is on a Unix-like server, often reached over SSH, so the platform list does not change its basic requirement: users need to administer the web server where certificates are installed.

Who it's for

Certbot suits people comfortable with the command line who run a website on a dedicated server, VPS, or cloud-hosted server. It is most compelling when they want certificate installation and renewal automated without paying for software. For most shared hosting users, asking the hosting provider to configure HTTPS is usually easier and more reliable.

Pros and cons

Pros

  • Free and open source: Certificate automation comes without a software charge, making it accessible to administrators on any budget.
  • Automated renewal: Renewing based on remaining certificate lifetime reduces manual date tracking.
  • Multiple setup methods: Apache, Nginx, webroot, standalone, and DNS validation give administrators options for different server circumstances.
  • DNS validation flexibility: It can work without an existing HTTP site or open port 80.

Cons

  • Requires server administration: The command-line workflow is a hurdle for users who cannot manage their own server.
  • Weak fit for shared hosting: Provider-managed HTTPS is generally easier and more reliable in that environment.
  • No certificate discovery: Certbot does not provide this capability, limiting its role in environments that need to locate certificates across systems.

Alternatives

Certificate Management Software is a useful category page for comparing other tools in this area.

  • Certify The Web is worth considering if its free evaluation or freemium model better fits your selection process; it supports a wider range of listed platforms, including API and web.
  • Qualys External Attack Surface Management may suit users who want to try a freemium product with a 30-day no-cost plan, rather than Certbot’s free, open-source server workflow.
  • Oracle Cloud Infrastructure Secret Management is an alternative for readers seeking a free secrets-management product with API and web platforms.
  • AWS Certificate Manager offers a free public-certificate plan for integrated AWS services; choose it if that AWS-specific scope fits better than managing certificates through Certbot.
  • KeyTalk CKMS is a paid option with a trial and support for mobile, desktop, Linux, and self-hosted platforms.
  • Entrust Certificate Manager is a paid alternative for readers considering a commercial certificate management product.
  • ManageEngine Key Manager Plus is a freemium alternative with a trial and an on-premises license for 25 managed keys at 59.00 USD per month.
  • Keyfactor Platform is a paid option with a trial for readers considering certificate lifecycle automation.

Verdict

Choose Certbot if you administer your own server and want free, open-source automation for obtaining, installing, and renewing Let’s Encrypt certificates. Its renewal automation and multiple validation methods are useful strengths. Look elsewhere if you rely on shared hosting or need certificate discovery; provider-managed HTTPS is the more suitable route for most shared hosting users.

Certbot plans and pricing

All plans
Certbot Free Free, open source software; automatically uses Let’s Encrypt certificates on manually administered websites certbot.eff.org · 3 Oct 2026

Compared on certificate management software

Free plan
Yescertbot.eff.org
Certificate discovery
Nocertbot.eff.org
Automatic renewal
Yescertbot.eff.org
Deployment automation
Yescertbot.eff.org
Revocation workflows
Yescertbot.eff.org
Certificate types
tlscertbot.eff.org
CA integrations
Yescertbot.eff.org

Facts

Purpose
Certbot automatically uses Let’s Encrypt certificates on manually administered websites to enable HTTPS.certbot.eff.org · 3 Oct 2026
Open source
Certbot is free, open source software.certbot.eff.org · 3 Oct 2026
Certificate renewal
Certbot renews certificates when less than one-third of their lifetime remains, or half their lifetime for certificates lasting 10 days or less.certbot.eff.org · 3 Oct 2026
Web server integration
The site names Apache and Nginx integrations and also describes webroot and standalone usage methods.certbot.eff.org · 3 Oct 2026
DNS validation
DNS validation does not require Let’s Encrypt to make an inbound connection to the server, so an existing HTTP site or open port 80 is not required for this method.certbot.eff.org · 3 Oct 2026
Command line
Certbot runs from a command-line interface, usually on a Unix-like server, and most users run it on a remote server over SSH.certbot.eff.org · 3 Oct 2026
Intended users
Certbot may suit people comfortable with the command line who administer a website on a dedicated server, VPS, or cloud-hosted server.certbot.eff.org · 3 Oct 2026
Shared hosting limitation
Certbot is less suitable for most shared hosting environments, where asking the provider to set up HTTPS is usually easier and more reliable.certbot.eff.org · 3 Oct 2026
HTTPS automation
Certbot can help obtain a certificate from a certificate authority and install it onto a web server automatically in many cases.certbot.eff.org · 3 Oct 2026
Support
The site points users to project documentation and the Let’s Encrypt community forum for help.certbot.eff.org · 3 Oct 2026
Security purpose
The project says it aims to help make the internet more structurally private, safe, and protected against censorship through HTTPS adoption.certbot.eff.org · 3 Oct 2026
Maker
Certbot is made by the Electronic Frontier Foundation, which the site describes as a 501(c)(3) nonprofit based in San Francisco, California.certbot.eff.org · 3 Oct 2026

Company

Headquarters
San Francisco, California, United Statescertbot.eff.org · 28 Sept 2026

Best Certbot alternatives

See all 20

Where it ranks on Everything Xiaomi

Is Certbot yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources