Introduction
HTTPS is mandatory for production. Let's Encrypt provides free certificates with automatic renewal.
Key Concepts
TLS Certificate: Cryptographic credential proving server identity.
Let's Encrypt: Free, automated Certificate Authority.
Certbot: Tool for obtaining and renewing certificates.
Deep Dive
Installing Certbot
bashsudo apt install certbot python3-certbot-nginx # Obtain certificate sudo certbot --nginx -d example.com -d www.example.com # Test renewal sudo certbot renew --dry-run
Nginx SSL Configuration
nginxserver { listen 443 ssl http2; server_name example.com; ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256; ssl_prefer_server_ciphers off; # HSTS add_header Strict-Transport-Security "max-age=31536000" always; }
Django Settings
pythonSECURE_SSL_REDIRECT = True SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') SESSION_COOKIE_SECURE = True CSRF_COOKIE_SECURE = True
Best Practices
- Use Let's Encrypt: Free, automatic, widely trusted.
- Enable HTTP/2: Better performance with SSL.
- Set up auto-renewal: Certbot does this automatically.
Summary
Use Let's Encrypt with Certbot for free SSL certificates. Configure Nginx for TLS 1.2/1.3 and enable HTTP/2 for better performance.