Let's Encrypt 는 ACME 프로토콜로 도메인 검증(DV) 인증서를 무료로 발급하는 공인 CA 다. 기본 인증서 유효기간은 90일이고, 6일짜리 단기 인증서도 선택할 수 있다[1]. 갱신을 자동화하는 것이 전제이므로 클라이언트 도구를 서비스로 등록해 둔다.
클라이언트는 EFF 의 certbot 을 쓴다. 현재 5.8.0 이며 snap 또는 pip 로 설치한다[2]. 예전의 certbot-auto 스크립트는 유지보수가 끝났고 공식 문서가 제거를 안내한다.
도메인 검증 방식은 둘이다[3].
| 방식 | 조건 | 와일드카드 |
|---|---|---|
| HTTP-01 | 80 포트가 인터넷에서 열려 있어야 한다 | 불가 |
| DNS-01 | DNS 에 _acme-challenge TXT 레코드를 넣을 수 있어야 한다 |
가능 |
systemd 를 쓰는 대부분의 배포판에서 같은 절차다.
# RHEL 계열
dnf install -y epel-release
dnf install -y snapd
systemctl enable --now snapd.socket
ln -s /var/lib/snapd/snap /snap
snap install core
snap refresh core
snap install --classic certbot
ln -s /snap/bin/certbot /usr/bin/certbot
certbot --version
snap 을 쓸 수 없는 환경에서만 쓴다. 가상환경 안에서만 지원한다.
dnf install -y python3 augeas-libs
python3 -m venv /opt/certbot
/opt/certbot/bin/pip install --upgrade pip
/opt/certbot/bin/pip install certbot
ln -s /opt/certbot/bin/certbot /usr/bin/certbot
웹 서버가 없으면 certbot 이 잠시 80 포트를 직접 연다.
certbot certonly --standalone -d www.example.com -d example.com
nginx · Apache 가 이미 떠 있으면 플러그인이 설정까지 손본다.
certbot --nginx -d www.example.com
certbot --apache -d www.example.com
certbot certonly --manual --preferred-challenges dns -d "*.example.com" -d example.com
진행 중 다음처럼 TXT 레코드 값을 보여 준다.
Please deploy a DNS TXT record under the name
_acme-challenge.example.com with the following value:
j8NXM0-tN6wYMouksE4oHMTLFm3XGKM29ZNLF7GB3B0
Before continuing, verify the record is deployed.
DNS 에 다음 레코드를 만들고, 전파된 것을 확인한 뒤 Enter 를 누른다.
_acme-challenge.example.com. TXT "j8NXM0-tN6wYMouksE4oHMTLFm3XGKM29ZNLF7GB3B0"
dig +short TXT _acme-challenge.example.com
TXT 레코드가 없으면 unauthorized · No TXT record found 로 실패하고, 같은 도메인으로 짧은 시간에 여러 번 실패하면 rate limit 에 걸려 한 시간 기다려야 한다[4]. 수동 DNS-01 은 자동 갱신이 안 되므로 운영에서는 DNS 제공자 플러그인(certbot-dns-*)을 쓴다.
발급되면 /etc/letsencrypt/live/<도메인>/ 아래에 심볼릭 링크 네 개가 생긴다. 갱신하면 링크가 새 파일을 가리키므로 서비스 설정에는 이 경로를 그대로 적는다.
| 파일 | 내용 |
|---|---|
privkey.pem |
비밀키 |
cert.pem |
서버 인증서 |
chain.pem |
중간 CA 체인 |
fullchain.pem |
cert.pem + chain.pem |
Apache httpd 에 적용하는 예다.
SSLCertificateFile /etc/letsencrypt/live/example.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem
nginx 는 ssl_certificate 에 fullchain.pem, ssl_certificate_key 에 privkey.pem 을 준다. IIS 등 PKCS#12 가 필요한 곳은 인증서 변환 을 본다.
openssl pkcs12 -export -in fullchain.pem -inkey privkey.pem -out example.com.pfx
snap 으로 설치하면 snap.certbot.renew.timer 가 하루 두 번 certbot renew 를 돈다. pip 로 설치했으면 cron 이나 systemd timer 를 직접 만든다.
systemctl list-timers | grep certbot
certbot renew --dry-run
갱신 뒤 서비스를 다시 읽게 하려면 --deploy-hook 을 쓴다.
certbot renew --deploy-hook "systemctl reload nginx"
certbot certificates
openssl s_client -connect www.example.com:443 -servername www.example.com </dev/null 2>/dev/null | openssl x509 -noout -issuer -dates
위 버전과 저장소는 오래된 것이라 저장소가 존재하지 않을 수 있다.
CentOS 7 의 EPEL 로 certbot 1.7.0 을 설치하고 certbot-auto 를 받아 썼다.
yum -y install certbot
wget https://dl.eff.org/certbot-auto
chmod 755 certbot-auto
와일드카드 발급 명령과 DNS TXT 검증 흐름은 지금과 같다.
certbot certonly --manual -d "*.example.com"
발급 결과는 /etc/letsencrypt/live/example.com/ 아래 fullchain.pem · privkey.pem 으로 저장됐고, 유효기간은 90일이었다.
Let's Encrypt FAQ — 인증서 유효기간 90일, 단기 6일 옵션, 와일드카드는 DNS-01. 2026-09-20 확인. https://letsencrypt.org/docs/faq/ ↩︎
certbot 최신 5.8.0 — 2026-09-20 확인. https://github.com/certbot/certbot/releases/latest · 설치 안내 https://eff-certbot.readthedocs.io/en/stable/install.html ↩︎
Let's Encrypt — Challenge Types. 2026-09-20 확인. https://letsencrypt.org/docs/challenge-types/ ↩︎
Let's Encrypt — Rate Limits. 2026-09-20 확인. https://letsencrypt.org/docs/rate-limits/ ↩︎