Call certbot

[sudo] certbot certonly --manual --preferred-challenges dns

Enter in domain name(s) in interest

Please enter in your domain name(s) (comma and/or space separated)  (Enter 'c'
to cancel): yourdomain.com

certbot demands you to deploy a DNS TXT record. Visit your DNS provider and deploy the TXT DNS. Wait for a while it is applied and press Enter

Please deploy a DNS TXT record under the name
_acme-challenge.yourdomain.com with the following value:
 
CiL7TfMMGHshG7TSEBql-eyz3JFkNvIyBOQh68qTjrM
 
Before continuing, verify the record is deployed.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Press Enter to Continue

If you see a message like below, it’s done. Configure your server properly

IMPORTANT NOTES:
 - Congratulations! Your certificate and chain have been saved at:
   /etc/letsencrypt/live/yourdomain.com-0001/fullchain.pem
   Your key file has been saved at:
   /etc/letsencrypt/live/yourdomain.com-0001/privkey.pem
   Your cert will expire on 2020-06-04. To obtain a new or tweaked
   version of this certificate in the future, simply run certbot
   again. To non-interactively renew *all* of your certificates, run
   "certbot renew"