This guide explains step-by-step how to create an SSL certificate using Let's Encrypt on Ubuntu and how to activate it for your website via the Plesk Panel.
Step 1: Update the System and Install Certbot
First, update your system packages:
sudo apt update
Then, install Certbot, the tool used to generate the SSL certificate:
sudo apt install certbot
Step 2: Generate a CSR (Certificate Signing Request) and Private Key Using OpenSSL
Run the following command in the terminal to create your CSR and Private Key:
openssl req -new -newkey rsa:2048 -nodes -keyout wwwmustafasonmez.comtr.key -out wwwmustafasonmez.comtr.csr
Note:When prompted for "extra attributes," simply press Enter to skip:
A challenge password []: (Press Enter)
An optional company name []: (Press Enter)
After completing this, two files will be created in your current directory:
wwwmustafasonmez.comtr.key→ Private Keywwwmustafasonmez.comtr.csr→ CSR file
Step 3: Generate the SSL Certificate Using the Existing CSR
Now, use the CSR file you just created to request the SSL certificate.
Run the following command:
sudo certbot certonly --manual --preferred-challenges http --csr wwwmustafasonmez.comtr.csr
If You Need a Wildcard SSL (for all subdomains):
For wildcard SSL certificates, validation must be performed via DNS records. Use the following command:
sudo certbot certonly --manual --preferred-challenges dns -d "*.mustafasonmez.com.tr" -d mustafasonmez.com.tr
Certbot will then guide you through the necessary DNS validation steps.
Step 4: Domain Validation
Certbot will prompt you with a message like this:
Create a file containing just this data: M3PsLxTGPG__uMLFAb2givLqG4cUr-J6aeZgW7euWvw.ZezkiO6wBT6Bf2wPj9YLPkYqPY4XmROY-4ZC7-AiXug
And make it available on your web server at this URL: http://www.mustafasonmez.com.tr/.well-known/acme-challenge/M3PsLxTGPG__uMLFAb2givLqG4cUr-J6aeZgW7euWvw
What you need to do:
Create the
.well-known/acme-challenge/directory on your web server if it does not already exist.Create a file containing only the specified token and upload it to the indicated URL.
After uploading the file, return to the terminal and press Enter to proceed.
If everything is correctly set up, you will see a message like this:
Successfully received certificate.
Certificate is saved at: /root/0001_cert.pem
Intermediate CA chain is saved at: /root/0002_chain.pem
Full certificate chain is saved at: /root/0003_chain.pem
This certificate expires on: 2025-07-14
Step 5: Prepare the Certificates for Plesk Panel
Now, convert the generated .pem files into a format that Plesk can understand.
First, create a new directory:
mkdir ~/ssl_ready_for_plesk_www_mustafasonmez.com_tr
Copy the necessary files into this directory:
cp www_mustafasonmez.com_tr.key ~/ssl_ready_for_plesk_www_mustafasonmez.com_tr/ cp ~/0001_cert.pem ~/ssl_ready_for_plesk_www_mustafasonmez.com_tr/www_mustafasonmez.com_tr.crt cp ~/0002_chain.pem ~/ssl_ready_for_plesk_www_mustafasonmez.com_tr/www_mustafasonmez.com_tr-ca.crt
You will now have the following files inside the directory:
wwwmustafasonmez.comtr.key(Private Key)wwwmustafasonmez.comtr.crt(SSL Certificate)wwwmustafasonmez.comtr-ca.crt(Intermediate CA Certificate)
Download these files to your computer.
Step 6: Upload and Activate the SSL Certificate in Plesk Panel
Log in to Plesk Panel.
Select your website and go to the SSL/TLS Certificates section.
Click on Add SSL/TLS Certificate.
Fill in the fields with the corresponding file contents:
Save the certificate.
Assign the newly uploaded certificate to your website.
✅ Your website is now protected with a Let's Encrypt SSL certificate valid for 90 days!
