What it is
The padlock in the address bar. It encrypts what a visitor types on the site and confirms the site is genuine. Without it browsers say "not secure" and search engines rank lower.
How we use it
Let's Encrypt certificates are issued and renewed automatically on the edge nginx; nobody has to remember them.
Where HTTPS matters to a business
- Without the padlock the browser says "not secure", and a visitor leaves without sending a request.
- A Telegram Mini App opens only from an HTTPS address, so an in-bot account or guide will not work without a certificate.
- A website form carries phone numbers and names, and they must not travel in plain text.
- A certificate expires over the weekend, and on Monday morning the site does not open.
How we use it
- Automatic renewal. On the websites server Let's Encrypt certificates are issued by certbot with a webroot check, so nginx never has to stop. Renewal runs on a timer, and a post-renewal hook makes nginx re-read the certificate without a restart. A check script shows the remaining lifetime for every site, with an alert threshold of under 20 days.
- Changing a domain without drops. On the VPN route one script moves the route to a new domain: the certificate, the nginx config and the subscriptions. Live sessions survive because nginx reloads its config instead of restarting.
- DNS validation. The demo host for the packaging manufacturer's sites cannot answer HTTP checks because of server-side restrictions, so its certificate is issued with DNS-01 validation.
- Static pages with HTTPS. The VPN setup guides live on GitHub Pages: HTTPS is already there, and Telegram will not open a Mini App without it.
HTTPS is part of every website and server deployment under Infrastructure.
Common problems
- certbot updated the files, nginx serves the old one. Without a post-renewal hook nginx keeps the old certificate in memory until it expires. That is exactly what happened on the VPN route before the fix.
- The certificate will not issue. For a second node in Russia a certificate could not be issued, and one of the sites ran without HTTPS for a while. That was one of the reasons the sites moved to a separate server.
- The server cannot answer the check. DNS-01 helps: domain ownership is proved by a DNS record.
- Requests to a bare IP. The entry nginx rejects such a handshake and closes the connection: the server's address alone reveals no site.
When you do not need it
You do not need your own certificate if the site lives on a host that provides HTTPS itself. And VLESS Reality on a VPN exit node works without any domain or certificate at all, because its disguise works differently.