Ribbon Icon Celebrating 27 Years – Announcing the new GeoTrust Horizon® platform. Learn More
Home Icon > Resources > Expert Guides > SSL/TLS Installation and Automation > How to Automatically Install SSL on Ubuntu NGINX

How to Automatically Install SSL on Ubuntu NGINX

Automated SSL installation is, to put it mildly, a game changer. Setting up SSL manually on Ubuntu can feel like a whirlwind of seemingly endless tasks:

While manual methods give you full control, they also leave plenty of room for error.

That’s why automatic SSL installation is quickly becoming the industry standard. Using an automated solution:

  • saves time,
  • frees you up to focus on other tasks and priorities,
  • reduces manual misconfiguration-related risks, and
  • ensures your website is secured with HTTPS quickly.

👉 If you still prefer manual installation, check out our detailed guide: How to Install SSL Certificate on NGINX in Ubuntu (Manual / Automated).

Automate Your SSL Certificate in 5 Minutes

Keep your website secure and online… no manual certificate renewals needed!

Step-by-Step Guide: How to Automatically Install SSL on Ubuntu NGINX

Step 1: Prepare Your Ubuntu Server

Before you start, ensure your Ubuntu server is running and NGINX is installed.

Check if NGINX is active:

sudo systemctl status nginx

If not installed yet, run:

sudo apt update
sudo apt install nginx -y

Step 2: Choose Your SSL Certificate

You need an SSL/TLS certificate before you can enable HTTPS.

  • If you already have one, make sure your files are ready.
  • If not, you can get a publicly trusted SSL/TLS certificate through us.

GeoTrust Horizon offers standard and wildcard SSL certificates — the latter is perfect if you want to secure multiple subdomains.

Step 3: Use an SSL/TLS Automation Agent

Most modern SSL setups use an automation agent to simplify installation. These agents relieve you of monotonous tasks like domain validation, installing certificates, and setting up renewals by doing it automatically.

Automate Your SSL Certificate in 5 Minutes

Keep your website secure and online… no manual certificate renewals needed!

GeoTrust Horizon AutoInstall SSL (for Ubuntu + NGINX)

If you’re a GeoTrust Horizon user, AutoInstall SSL makes this process seamless:

  1. Sign in to the GeoTrust Horizon Dashboard.
  2. Go to your SSL/TLS certificate management page.
  3. Select AutoInstall SSL.
A demonstration showing how to select SSL automation as your installation method
Image caption: The GeoTrust Horizon dashboard displays manual and automated (AutoInstall SSL) method options for installation.
  1. Choose:
    • Operating System: Ubuntu
    • Web Server: NGINX
A demonstration showing where to select your specific server type (in this case, NGINX)
Image caption: A screenshot of the GeoTrust Horizon dashboard showing the AutoInstall SSL option for NGINX servers.

Step 4: Generate Your AutoInstall SSL API Key

Automation tools require authentication. In the GeoTrust Horizon platform, this happens via an AutoInstall SSL API Key.

  • This API key ensures secure communication between your server and GeoTrust Horizon.
  • It allows AutoInstall SSL to configure DNS records (if needed), install certificates, and handle renewals.

In GeoTrust Horizon:

  • Under your existing GeoTrust Horizon Orders page, click the Manage button to bring up your certificate order. Scroll down to the AutoInstall SSL section. There, you’ll find your AutoInstall SSL token (AutoInstall SSL API key).
A demonstration showing where to find your AutoInstall SSL token value
Image caption: A screenshot showing where to locate the AutoInstall SSL API token in the GeoTrust Horizon dashboard.
  • In your DNS provider’s dashboard, copy your access key and secret access key. (You’ll use both of these resources in the next step.)
  • Now, switch over to your server’s terminal.

Related resource: Using DNS Validation with AutoInstall SSL

Step 5: Download and Run the AutoInstall Script

From the GeoTrust Horizon dashboard, copy the generated installation command and run it in your terminal:

sudo wget -qO - https://files.autoinstallssl.com/packages/linux/version/latest/get.autoinstallssl.sh | sudo bash -s

The script will ask for your DNS provider’s API access key and secret access key. Once provided, it will:

  • Validate your domain
  • Install the SSL certificate in NGINX
  • Reload your server configuration

Step 6: Verify Installation

After installation, restart NGINX using the following command:

sudo systemctl restart nginx

Now visit the secure version of your site by adding https:// to the beginning of the URL (e.g., https://yourdomain.com). (In Chrome, you must double-click on it to make the https:// appear.) You should see a padlock in the browser’s web address bar or a “Connection is secure” type of message.

An example of an SSL/TLS certificate on GeoTrust.com, which ensures secure connections for users

That’s it! Barring no issues or misconfigurations, your site should be good to go. AutoInstall SSL will handle your SSL/TLS certificate renewal and installation processes automatically in the future.

FAQs About Automating SSL on Ubuntu NGINX

Q1: Do I need root access for AutoInstall SSL?

Yes. Root (or sudo) access privileges are required to configure NGINX and update DNS settings.

Q2: What if my DNS provider isn’t supported?

GeoTrust Horizon supports most major providers. If yours isn’t listed, you can:

  • Complete the domain validation process manually by adding records in your DNS provider’s panel.
  • Reach out to our GeoTrust Horizon Support team via the dashboard to request support for additional DNS providers.

Q3: Does AutoInstall SSL handle renewals?

Yes. Certificates are renewed automatically before expiry, so your site always stays secure.

Q4: Can I use AutoInstall SSL with a wildcard SSL certificate?

Absolutely. Wildcard SSL certificates are fully supported, securing unlimited (single-level) subdomains with one certificate.