Install SSL on Emby & Immich on Windows 10 machine (update 10 comes later). Immich is first Emby later
Budget: €250 – €750 EUR
I run two separate Windows 10 boxes: one hosts an Emby media server, the other an Immich photo-backup server. I want both services to be reachable over HTTPS with a valid Let’s Encrypt certificate instead of the self-signed setups I have now.
Where I’m at
• Domains and DNS are already in place and pointing to each machine via dynamic DNS.
• I have not yet generated the certificates, nor have I settled on which web server (IIS, Nginx, Apache, or a lightweight alternative) makes the most sense for these apps under Windows. I’ll need your guidance here.
What I need from you
1. Advise on the cleanest path to obtain and renew Let’s Encrypt certificates on Windows 10—whether that’s using Certbot, win-acme, or another tool.
2. Configure the chosen ACME client, generate the certs, and install them so Emby and Immich both serve traffic exclusively over HTTPS.
3. Set up automated renewal with zero downtime.
4. Document the steps you take so I can replicate the process later if I move machines.
Acceptance criteria
• Browsers show a valid Let’s Encrypt padlock on both servers.
• Automatic renewal tested successfully (dry-run or short-dated cert).
• Services start with Windows without manual intervention and stay behind HTTPS by default.
Remote access via AnyDesk or similar is fine, or you can walk me through it if you prefer. Let me know your proposed approach and timeline, and we can get started right away.
Where I’m at
• Domains and DNS are already in place and pointing to each machine via dynamic DNS.
• I have not yet generated the certificates, nor have I settled on which web server (IIS, Nginx, Apache, or a lightweight alternative) makes the most sense for these apps under Windows. I’ll need your guidance here.
What I need from you
1. Advise on the cleanest path to obtain and renew Let’s Encrypt certificates on Windows 10—whether that’s using Certbot, win-acme, or another tool.
2. Configure the chosen ACME client, generate the certs, and install them so Emby and Immich both serve traffic exclusively over HTTPS.
3. Set up automated renewal with zero downtime.
4. Document the steps you take so I can replicate the process later if I move machines.
Acceptance criteria
• Browsers show a valid Let’s Encrypt padlock on both servers.
• Automatic renewal tested successfully (dry-run or short-dated cert).
• Services start with Windows without manual intervention and stay behind HTTPS by default.
Remote access via AnyDesk or similar is fine, or you can walk me through it if you prefer. Let me know your proposed approach and timeline, and we can get started right away.
Related categories:
System Admin
Linux
Web Security
Apache
IIS
Nginx
Windows Server
Documentation
Network Security
SSL