Merchant & operations
HTTPS with Certbot
Add and renew an HTTPS certificate for an Agovena store behind Nginx or Apache.
On this page
Use this guide after you have configured one web server. HTTPS protects login, Admin, checkout and provider callbacks. It does not replace the Agovena scheduler cronjob.
1. Check DNS and ports
Before requesting a certificate:
- Point the DNS record for
store.exampleto this server. - Allow inbound TCP ports 80 and 443 in the firewall.
- Make sure the selected web server can answer on port 80.
- Replace
store.examplein every command with the real hostname.
2. Install Certbot
Choose your operating system. Both Certbot web server plugins are installed so you can use the Nginx or Apache command in the next step:
sudo apt update
sudo apt install -y certbot python3-certbot-nginx python3-certbot-apache
sudo apt-get update
sudo apt-get install -y certbot python3-certbot-nginx python3-certbot-apache
3. Request the certificate
Run the command for the web server you use:
sudo certbot --nginx -d store.example
sudo certbot --apache -d store.example
Certbot can update the selected virtual host and redirect HTTP to HTTPS. Review the resulting configuration, then set this value in /var/www/agovena/.env:
APP_URL=https://store.example
4. Test certificate renewal
Certbot installs a renewal timer with the package. Check the timer and run a dry run:
sudo systemctl enable --now certbot.timer
sudo systemctl status certbot.timer
sudo certbot renew --dry-run
Do not create a second renewal cronjob when the Certbot timer is already active. The Agovena cronjob is separate and still needs to run schedule:run every minute.
5. Check HTTPS
Open the store, /login, /admin and a checkout page using https://. Confirm that HTTP redirects to HTTPS, the certificate hostname matches and provider callbacks use the HTTPS URL. Then run:
cd /var/www/agovena
php artisan agovena:doctor