Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: eradanenov.tk
I ran this command: sudo certbot
It produced this output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
How would you like to authenticate and install certificates?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Apache Web Server plugin (apache)
2: Nginx Web Server plugin (nginx)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 2
Plugins selected: Authenticator nginx, Installer nginx
Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org
No names were found in your configuration files. Please enter in your domain
name(s) (comma and/or space separated) (Enter 'c' to cancel): eradanenov.tk
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for eradanenov.tk
Waiting for verification...
Challenge failed for domain eradanenov.tk
http-01 challenge for eradanenov.tk
Cleaning up challenges
Some challenges have failed.
IMPORTANT NOTES:
- The following errors were reported by the server:
Domain: eradanenov.tk
Type: dns
Detail: DNS problem: query timed out looking up CAA for tk
My web server is (include version): nginx/1.16.1
The operating system my web server runs on is (include version): CentOS 7
My hosting provider, if applicable, is: NA
I can login to a root shell on my machine (yes or no, or I don’t know): yes
I’m using a control panel to manage my site (no, or provide the name and version of the control panel): No
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot): certbot 0.39.0
If the project is minimal important, I wouldn't use a free service.
Free services have often limitations, sometimes they are hidden. Sample: You have a "free" domain, but everyone can create subdomains with that domain name -> that hits the Letsencrypt subdomain limit. Or you have a "free" domain, someone want's to use that domain and pays -> your domain is gone.
And you may have such problems like not working name servers.
Thank you @JuergenAuer, @patrakov for your responses. This is a project for demo purposes only - expected to be up for a few months only. My idea was to use a free option initially and then a paid one once the demo is done.
If you're using a Freenom domain, you could still use Cloudflare for DNS--they're free, and they're generally considered to be pretty good (I've been happy with them for the last few years).