Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To enable HTTPS on Apache, enable mod_ssl, configure a virtual host on port 443, point it to the certificate and matching private key, test the configuration, then reload or restart Apache. With Certbot on Apache 2.4.8 or later, use fullchain.pem for SSLCertificateFile and privkey.pem for SSLCertificateKeyFile.

Before you install the certificate

You need an Apache installation with OpenSSL support and the SSL module, a certificate and its matching private key, and a hostname that resolves to this server. Ensure inbound TCP port 443 is allowed by the server firewall and any cloud firewall. If you will obtain a certificate using ACME HTTP validation, the required HTTP challenge path must also be reachable during issuance.

  • Confirm the certificate covers the exact hostname visitors will use, including whether it is the bare domain, a www subdomain, or both.
  • Identify the Apache configuration file for that host. Debian- and Ubuntu-based systems commonly use sites-available; Red Hat-family systems commonly use conf.d. Paths and enablement commands vary by distribution.
  • Keep the private key outside the web document root and out of source control.

Apache HTTPS is provided by mod_ssl, which interfaces with OpenSSL. The directives and certificate files below are the same whether the certificate came from a commercial certificate authority or an ACME client; the difference is how you obtain, renew, and deploy the files.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the certificate files Apache needs

Certbot on Apache 2.4.8 and later

Certbot stores certificate material under /etc/letsencrypt/live/<domain>/. For Apache 2.4.8 or later, configure SSLCertificateFile to use fullchain.pem, which contains the server certificate followed by intermediate certificates. Set SSLCertificateKeyFile to privkey.pem, the corresponding private key.

  • /etc/letsencrypt/live/www.example.com/fullchain.pem: leaf certificate followed by intermediate certificates.
  • /etc/letsencrypt/live/www.example.com/privkey.pem: private key; treat it as a secret.

Separate certificate and chain files

Older Apache arrangements may use separate files: cert.pem for the leaf certificate and chain.pem for intermediates. Follow the requirements for the Apache version and configuration you operate; omitting intermediate certificates can cause browsers to report an incomplete or untrusted chain. Do not substitute a chain-only file for the server certificate.

Commercial CA files

A certificate authority may provide a leaf certificate, an intermediate bundle, and sometimes a private key generated on your server. Identify which file contains the leaf certificate, which contains intermediates, and which private key matches the certificate before editing Apache. File names differ between providers, so use the CA’s file description rather than assuming a particular filename.

Configure an HTTPS virtual host

Apache’s SSL/TLS how-to describes the essential configuration as a listener on 443, SSLEngine on, a certificate file, and a key file. Adapt this example to your hostname and document root:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
LoadModule ssl_module modules/mod_ssl.so
Listen 443
<VirtualHost *:443>
    ServerName www.example.com
    SSLEngine on
    SSLCertificateFile "/etc/letsencrypt/live/www.example.com/fullchain.pem"
    SSLCertificateKeyFile "/etc/letsencrypt/live/www.example.com/privkey.pem"
    DocumentRoot "/var/www/www.example.com"
</VirtualHost>

The LoadModule line is shown to illustrate the module requirement; many distribution packages enable the module through their own configuration or tooling, so do not add a duplicate module load blindly. Likewise, ensure there is one effective listener on port 443 and put the virtual host in the appropriate enabled configuration. Set ServerName to the hostname covered by the certificate and DocumentRoot to the site’s actual content directory. Add ServerAlias values only for additional hostnames that the certificate covers.

Enable the SSL module and site

Use the enablement mechanism for your operating system or hosting environment to activate the SSL module and the virtual-host configuration. On Debian/Ubuntu, virtual hosts are often maintained in sites-available and enabled separately; on Red Hat-family systems, configurations are often loaded from conf.d. Managed hosting may require using its control panel instead of editing Apache files directly.

Protect the private key

The private key is not a public certificate file. Certbot explicitly warns that privkey.pem must be kept secret and never shared. Apache reads the key when starting, so the service must be able to read it. Apache documentation advises restricting key access; the exact owner, group, and mode depend on whether the service starts as root and how the platform drops privileges.

  • Keep the key outside the document root and exclude it from repositories, backups shared with untrusted parties, and logs.
  • Grant only the minimum read access required by Apache’s privilege model. Do not make the key world-readable just to bypass a permissions error.
  • If a key is encrypted, Apache may require its pass phrase at startup unless you have configured an approved pass-phrase mechanism. Plan for unattended service restarts accordingly.

Test the configuration and apply it

  1. Run the configuration test for your platform, commonly apachectl configtest or apache2ctl configtest.
  2. Resolve every syntax, missing-file, certificate/key mismatch, and permission error reported before applying the change.
  3. Reload Apache to apply a valid configuration. If you changed module loading or the service cannot reload, use a full restart appropriate to your operating system.
  4. Check the service status and Apache error log if the reload or restart fails.

Apache reads certificate and key files at startup; a change to those files does not necessarily reach the running server until Apache reloads or restarts. A successful configuration test checks syntax and file access, but it does not prove that the public endpoint serves the expected certificate.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify the certificate served to visitors

Open the HTTPS URL in a browser and inspect the certificate’s hostname and trust status. From a shell, use OpenSSL to inspect the live endpoint and its certificate chain:

openssl s_client -connect www.example.com:443 -servername www.example.com -showcerts

The -servername option supplies the TLS server name, important when Apache hosts multiple HTTPS virtual hosts on one address. Check that the served certificate’s subject alternative names cover the hostname, the chain includes the necessary intermediates, and the negotiated protocol meets your operational requirements. If OCSP stapling is enabled and you need to inspect it, Apache’s how-to documents using openssl s_client with -status and -servername.

Renew a Certbot certificate without breaking HTTPS

Certbot updates the files in the live directory during renewal. Point Apache directly at those paths rather than copying certificate files to a second location; otherwise, the copied files can become stale. After renewal, arrange for Apache to reload so the running process reads the updated certificate.

  1. Keep SSLCertificateFile and SSLCertificateKeyFile pointed at the relevant /etc/letsencrypt/live/<domain>/ paths.
  2. Run a renewal test using the renewal procedure appropriate to your Certbot installation and environment.
  3. Configure and verify a deploy or post-renewal hook to test the Apache configuration and reload Apache after a successful renewal.
  4. Check the public endpoint after renewal to confirm it presents the renewed certificate and complete chain.

Renewal automation has two separate jobs: obtaining updated files and getting the running web server to serve them. A successful renewal alone does not confirm that Apache reloaded them.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common Apache SSL installation errors

Apache prompts for a pass phrase or will not start

The private key may be encrypted. Apache’s SSL module needs access to the key at startup and may prompt for its pass phrase. For an unattended service, use an approved pass-phrase handling approach for your environment rather than removing protection or placing a secret in an exposed script.

Rank #4
Sale
Adams Gift Certificate Book, Carbonless, Single Paper, 3.4 x 8 Inches, White/Canary, 2-Part, 25 Numbered Certificates Plus Store Sign (GFTC1)
  • 2-part carbonless unit set
  • Consecutive numbering
  • Includes Gift Certificates Available sign
  • 25 certificates with envelopes per package
  • White/canary form sequence

Browser reports an incomplete or untrusted chain

On Apache 2.4.8 or later with Certbot, use fullchain.pem as the certificate file. If using an older arrangement with separate files, configure the leaf certificate and intermediate chain as required for that Apache version. Confirm the live server is serving the intended chain with a TLS inspection tool.

Permission denied for privkey.pem

Apache cannot read the key under its current service permissions. Preserve the key’s secrecy and grant the daemon only the minimum required access using the ownership and group model supported by your distribution. Then rerun the configuration test and restart or reload as needed.

The replacement certificate is not visible

Apache may still be serving the certificate it loaded earlier. Test the configuration, then reload or restart the service so it reads the updated files. Verify the endpoint again instead of relying only on the files’ modification time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The wrong certificate appears for a hostname

Check the selected *:443 virtual host, its ServerName and ServerAlias values, and whether another default virtual host is handling the request. Ensure the certificate attached to the selected host covers the requested name.

Configuration test reports a missing file or syntax error

Check path spelling, file readability, directive placement, and whether SSL module configuration is enabled. A path that exists for an interactive administrator may still be unreadable to the service under its startup permissions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

Installing an SSL certificate on Apache is a server configuration task; ScreenshotNeo is not a certificate installer. If your next task is capturing a page screenshot for testing or documentation, ScreenshotNeo accepts a URL and returns an image or PDF without requiring you to set up a browser locally. It removes cookie/consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are never billed; and its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000.

Example request and options are documented at ScreenshotNeo’s API documentation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo also offers an MCP server for AI clients and PDF capture. Sign up for 1,000 free screenshots a month with no card.

Frequently Asked Questions

Does Apache need both a certificate file and a private key file?

Yes. The HTTPS virtual host needs a certificate configured with SSLCertificateFile and its matching private key with SSLCertificateKeyFile.

Can I install an SSL certificate through a hosting control panel?

Some managed hosts provide certificate installation and renewal through their control panel. The underlying Apache setup still needs a valid certificate, matching key, and HTTPS virtual host, but the host may manage those files and service changes for you.

Can the same certificate cover both example.com and www.example.com?

Only if both hostnames are included in the certificate’s names. Check its subject alternative names and configure Apache’s hostnames accordingly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.