whatis tls-certificate
TLS Certificate
Also known as: SSL certificate, Let's Encrypt, HTTPS certificate
A signed file that proves a server's identity and enables encrypted HTTPS connections. Let's Encrypt issues them for free.
What Is a TLS Certificate?
A certificate binds a domain name to a public key and is signed by a certificate authority browsers trust. The server keeps the matching private key and uses both to set up encrypted TLS sessions.
Let's Encrypt certificates last 90 days and are renewed automatically by clients like certbot or by servers like Caddy. For internal services you can create self-signed certificates or run your own CA with OpenSSL.
Example
sudo certbot --nginx -d example.com
openssl x509 -in cert.pem -noout -dates Learn more about TLS Certificate
- TLS Certificates on Linux: Let's Encrypt, certbot, and What Actually Happens Free automated certificates removed the last excuse for running services over plain HTTP. Here is how the ACME challenge works, how to get a certificate with certbot, and how to handle wildcards and renewal properly.
- OpenSSL, CSRs and Self-Signed Certificates: What Each Piece Is For A private key, a CSR and a certificate are three different things and people conflate all three. What actually gets signed, why SANs matter more than Common Name, and when a self-signed certificate is the right answer instead of a mistake.
Related tools
- OpenSSL CSR Builder Generate certificate signing request commands with subject fields and SAN entries filled in.