SSL ฟรีด้วย Let’s Encrypt 2026 ติดตั้งอย่างไรให้เว็บเป็น HTTPS
Free SSL with Let’s Encrypt in 2026: how to install via DirectAdmin and Certbot, auto-renewal, wildcard certificates and how secure it really is.
สารบัญ
Let’s Encrypt คืออะไร
Let’s Encrypt คือผู้ออกใบรับรอง (Certificate Authority) แบบไม่แสวงหากำไรที่ออก SSL/TLS ให้ฟรีและอัตโนมัติ ทำให้ทุกเว็บเปลี่ยนจาก HTTP เป็น HTTPS ได้โดยไม่มีค่าใช้จ่าย ปัจจุบันเป็น CA ที่ออกใบรับรองมากที่สุดในโลก
Let’s Encrypt is a non-profit Certificate Authority that issues SSL/TLS certificates for free and automatically, letting any website move from HTTP to HTTPS at no cost. It is now the most widely used CA in the world.
- ฟรี 100% ไม่มีค่าธรรมเนียมรายปี
- ออกใบรับรองอัตโนมัติผ่านโปรโตคอล ACME
- รองรับโดยโฮสติ้งและแผงควบคุมส่วนใหญ่
- เป็น DV (Domain Validation) ยืนยันการเป็นเจ้าของโดเมน
- ได้รับการยอมรับจากเบราว์เซอร์ทุกตัว
SSL ฟรีปลอดภัยพอไหมเทียบกับแบบเสียเงิน
หลายคนเข้าใจผิดว่า SSL ฟรีอ่อนแอกว่า ความจริงคือการเข้ารหัสเหมือนกันทุกประการ ทั้งฟรีและเสียเงินใช้ AES และ TLS 1.3 เหมือนกัน ความต่างอยู่ที่ระดับการตรวจสอบตัวตน ไม่ใช่ความแข็งแกร่งของการเข้ารหัส
A common myth is that free SSL is weaker. In reality the encryption is identical — both free and paid certificates use the same AES and TLS 1.3. The difference is the level of identity validation, not encryption strength.
- การเข้ารหัสเท่ากัน: AES-256, TLS 1.3
- แม่กุญแจในเบราว์เซอร์แสดงเหมือนกัน
- ต่างที่ระดับตรวจสอบ: Let’s Encrypt เป็น DV เท่านั้น
- เว็บทั่วไป บล็อก ร้านค้าเล็ก ใช้ DV เพียงพอ
- องค์กรใหญ่ที่ต้องแสดงชื่อบริษัทค่อยพิจารณา OV/EV
ติดตั้ง Let’s Encrypt ผ่านแผงควบคุม
วิธีที่ง่ายที่สุดคือใช้แผงควบคุมของโฮสติ้ง โฮสต์คุณภาพดีมักออกและต่ออายุ Let’s Encrypt ให้อัตโนมัติเพียงไม่กี่คลิก โดยไม่ต้องแตะบรรทัดคำสั่ง บนแผง DirectAdmin มีเมนู SSL Certificates ให้กดออกใบรับรองฟรีได้ทันที
The easiest route is your host’s control panel. Quality hosts issue and renew Let’s Encrypt automatically in a few clicks with no command line. In DirectAdmin, the SSL Certificates menu lets you issue a free certificate instantly.
- เข้าแผงควบคุม เลือกเมนู SSL Certificates
- เลือก "Free & automatic certificate from Let’s Encrypt"
- ติ๊กโดเมนและ www ที่ต้องการครอบคลุม
- กด Save แล้วเปิดใช้ Force HTTPS
- โฮสต์จะต่ออายุให้อัตโนมัติทุก 90 วัน
ติดตั้งด้วย Certbot บน VPS
ถ้าคุณดูแล VPS หรือเซิร์ฟเวอร์เอง สามารถใช้ Certbot ซึ่งเป็นเครื่องมือทางการของ Let’s Encrypt ออกใบรับรองและตั้งค่าให้เว็บเซิร์ฟเวอร์ Apache หรือ Nginx อัตโนมัติ พร้อมตั้ง cron ต่ออายุ
If you manage your own VPS or server, Certbot — the official Let’s Encrypt client — issues certificates and configures Apache or Nginx automatically, with a cron job for renewal.
- ติดตั้ง Certbot ผ่าน package manager ของระบบ
- รัน certbot --nginx หรือ certbot --apache
- Certbot แก้ไฟล์คอนฟิกและรีโหลดเซิร์ฟเวอร์ให้
- ตั้ง systemd timer/cron เพื่อ certbot renew อัตโนมัติ
- ทดสอบด้วย certbot renew --dry-run
Wildcard SSL ฟรีด้วย DNS Challenge
Let’s Encrypt ออก Wildcard (*.example.com) ได้ฟรีเช่นกัน แต่ต้องยืนยันผ่าน DNS Challenge แทน HTTP เหมาะกับเว็บที่มีหลายซับโดเมน เพราะใบเดียวครอบทุกซับโดเมนชั้นแรก
Let’s Encrypt also issues free wildcard certificates (*.example.com), but they must be validated with a DNS challenge instead of HTTP. This suits sites with many subdomains, since one certificate covers all first-level subdomains.
- Wildcard ครอบ blog./shop./api.example.com ในใบเดียว
- ต้องยืนยันผ่าน DNS-01 (เพิ่ม TXT record)
- บางแผงควบคุมและ Certbot plugin ทำ DNS challenge อัตโนมัติ
- ไม่ครอบซับโดเมนซ้อน เช่น a.b.example.com
- เหมาะกับระบบที่สร้างซับโดเมนบ่อย
ทำไมอายุ 90 วัน และต่ออายุอย่างไร
ใบรับรอง Let’s Encrypt มีอายุ 90 วัน ซึ่งสั้นกว่า SSL เสียเงินโดยตั้งใจ เพื่อความปลอดภัยและบังคับให้ระบบต่ออายุอัตโนมัติ หากตั้งค่าถูกต้อง คุณไม่ต้องทำอะไรเลย
Let’s Encrypt certificates last 90 days — deliberately shorter than paid SSL — for security and to encourage automated renewal. Configured correctly, you never have to touch it.
- อายุสั้นลดความเสี่ยงหากกุญแจรั่ว
- ระบบต่ออายุอัตโนมัติเมื่อเหลือ ~30 วัน
- โฮสต์ที่ดีจัดการให้เบื้องหลังทั้งหมด
- ควรตั้งแจ้งเตือนหากต่ออายุล้มเหลว
- อย่าปิด cron/timer ที่ทำหน้าที่ต่ออายุ
บังคับ HTTPS และแก้ Mixed Content
หลังติดตั้ง SSL อย่าลืมบังคับเปลี่ยนเส้นทาง HTTP ไป HTTPS และแก้ปัญหา Mixed Content คือลิงก์รูปหรือสคริปต์ที่ยังเป็น http:// ซึ่งทำให้แม่กุญแจไม่ขึ้นแม้มี SSL แล้ว
After installing SSL, force a redirect from HTTP to HTTPS and fix any mixed content — images or scripts still loaded over http:// — which stops the padlock appearing even with SSL active.
- เปิด Force HTTPS ในแผงควบคุม หรือ 301 redirect ใน .htaccess
- แก้ลิงก์ภายในให้เป็น https:// หรือ // (protocol-relative)
- ตรวจปลั๊กอิน/ธีมที่โหลดทรัพยากรผ่าน http
- ใช้ DevTools คอนโซลหาคำเตือน mixed content
- พิจารณาเปิด HSTS เมื่อมั่นใจว่า HTTPS ครบทุกหน้า
เลือกโฮสติ้งที่ทำ SSL ฟรีให้ง่าย
ประสบการณ์ SSL ที่ดีที่สุดคือ "ไม่ต้องคิดเลย" จากที่เราใช้งานจริง โฮสต์ที่ตั้ง Let’s Encrypt ให้อัตโนมัติบน DirectAdmin พร้อมต่ออายุเองและมีทีมไทยช่วยเหลือ ทำให้มือใหม่เปิด HTTPS ได้ในไม่กี่นาทีโดยไม่ต้องแตะคำสั่ง
The best SSL experience is one you never have to think about. In our hands-on use, a host that auto-provisions Let’s Encrypt on DirectAdmin, renews it for you and has a Thai support team lets beginners get HTTPS running in minutes without any commands.
- มองหา "Free SSL" หรือ "Let’s Encrypt" ในสเปกแพ็กเกจ
- แผง DirectAdmin ที่ออก SSL ได้ในคลิกเดียว
- ต่ออายุอัตโนมัติเป็นค่าเริ่มต้น
- ทีมซัพพอร์ตช่วยแก้ mixed content/redirect
- SSD และเซิร์ฟเวอร์ในไทยช่วยให้ HTTPS เร็วไม่หน่วง