# Order, validate and install an SSL certificate

> Create a key and CSR with OpenSSL, configure your SSL order, validate the domain and install the certificate on nginx, Apache, IIS, cPanel or Plesk.

Difficulty: Intermediate\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025

An SSL (TLS) certificate binds your domain to a key, so browsers can encrypt the connection and check that they reach the right server. This guide takes a purchased certificate from the private key to a working HTTPS site, and covers free certificates too. Replace `example.com` with your domain.

## Before you start

- The domain points to the server: [point a domain to your server](/guides/point-domain-to-server).
- Choose the type: **DV** (domain validation, minutes), **OV** or **EV** (organisation checks, usually a few business days) or a **wildcard** for all subdomains. See [SSL certificates](/ssl-certificates).
- On hosting plans, the included free certificate may already be all you need: check **SSL/TLS Status** in cPanel or **SSL/TLS Certificates** in Plesk.

## Step 1: Create a private key and CSR

On your server (or any Linux or macOS machine), create an ECDSA key and a certificate signing request that covers the domain and `www`:

```bash
openssl req -new -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -nodes -keyout example.com.key -out example.com.csr -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com,DNS:www.example.com"
```

If a system needs RSA, use `-newkey rsa:2048` instead of the two `ec` options. Protect the key:

```bash
chmod 600 example.com.key
openssl req -in example.com.csr -noout -text
```

**Verify:** the output shows your domain under `Subject` and `Subject Alternative Name`. The `.key` file stays on the server; you submit only the `.csr`.

## Step 2: Configure the certificate in the client area

1. Go to **Services › My Services** and open the SSL certificate service, then **Configure SSL Certificate** (or use **Manage SSL Certificates**).
2. Choose your server type, paste the full CSR including the `BEGIN` and `END` lines, and complete the contact details.
3. Choose a validation method, as offered for your certificate:
   - **Email:** approve the message sent to an address such as `admin@example.com` or `webmaster@example.com`.
   - **DNS:** publish the TXT or CNAME record you are given at your DNS host.
   - **HTTP file:** place the given file under `/.well-known/pki-validation/` on your site.

**Verify:** the order status moves to issued, and the certificate and CA bundle are delivered. DV certificates usually arrive within minutes of validation; OV and EV need the organisation checks first.

## Step 3: Install the certificate

Save the certificate as `example.com.crt` and the intermediate bundle as `ca-bundle.crt` next to the key, for example in `/etc/ssl/example.com/`. For nginx and Apache, combine them into a full chain:

```bash
cat example.com.crt ca-bundle.crt > fullchain.pem
```

**nginx**

```nginx
server {
    listen 443 ssl;
    listen [::]:443 ssl;
    server_name example.com www.example.com;

    ssl_certificate     /etc/ssl/example.com/fullchain.pem;
    ssl_certificate_key /etc/ssl/example.com/example.com.key;
}
```

Test and reload: `sudo nginx -t` and `sudo systemctl reload nginx`.
**Apache**

Enable the module, then set the files in the `VirtualHost` for port 443:

```bash
sudo a2enmod ssl
```

```apache
SSLEngine on
SSLCertificateFile    /etc/ssl/example.com/fullchain.pem
SSLCertificateKeyFile /etc/ssl/example.com/example.com.key
```

Test and reload: `sudo apachectl configtest` and `sudo systemctl reload apache2`.
**IIS**

Combine key, certificate and chain into a PFX file (on a Linux or macOS machine):

```bash
openssl pkcs12 -export -out example.com.pfx -inkey example.com.key -in example.com.crt -certfile ca-bundle.crt
```

In **IIS Manager › Server Certificates**, choose **Import** and select the PFX. (If you created the CSR in IIS, use **Complete Certificate Request** instead.) Then open the site's **Bindings**, add an **https** binding on port 443 with the host name and select the certificate.
**cPanel and Plesk**

- **cPanel:** **SSL/TLS › Manage SSL sites**: paste the certificate, the key and the CA bundle for the domain and install.
- **Plesk:** **SSL/TLS Certificates** for the domain: upload the certificate, key and CA bundle, then select the certificate in the hosting settings.

## Step 4: Check the result

```bash
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -issuer -dates
```

**Verify:** the subject is your domain, the issuer is your certificate authority, and `notAfter` is in the future. Open the site in a browser and check the padlock. Redirect HTTP to HTTPS once everything works.

## Free certificates with Certbot

On your own Linux server, Certbot obtains and renews Let's Encrypt certificates. Install it from the distribution packages and let it configure nginx:

```bash
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d example.com -d www.example.com
sudo certbot renew --dry-run
```

Use `python3-certbot-apache` and `--apache` for Apache. A step-by-step setup with a reverse proxy is in [nginx reverse proxy with Certbot](/guides/nginx-reverse-proxy-certbot).

## Renewals and CAA

Maximum certificate lifetimes are shrinking: 200 days since 15 March 2026, 100 days from 15 March 2027 and 47 days from 15 March 2029. Multi-year purchases are reissued within the term, and you install each new certificate, so automate where you can. If you publish a **CAA** record, list every certificate authority you use, including the one behind free certificates:

```bash
dig CAA example.com +short
```

## Troubleshooting

**The browser warns about an incomplete chain.** The CA bundle is missing; install the full chain.

**"Key values mismatch" or the server does not start.** The certificate does not belong to the key. Compare: `openssl x509 -noout -pubkey -in example.com.crt` and `openssl pkey -pubout -in example.com.key` must print the same key.

**Validation by email never arrives.** Use DNS or HTTP validation, or make sure the approver address exists.

**Validation fails because of CAA.** Add the issuing authority to your CAA record.

## Next steps

- Put Cloudflare in front with Full (strict): [Cloudflare setup](/guides/cloudflare-proxy-setup).
- Compare certificate types: [SSL certificates](/ssl-certificates).

## Frequently asked questions

### Do I need to buy a certificate?

Not always. Hosting plans include a free certificate, and on your own server Certbot gets free Let's Encrypt certificates. Buy a certificate when you need organisation or extended validation, a commercial wildcard or a specific brand.

### How long is a certificate valid?

Since 15 March 2026 a publicly trusted certificate can be valid for at most 200 days; the limit drops to 100 days on 15 March 2027 and to 47 days on 15 March 2029. Multi-year terms are subscriptions in which the certificate is reissued.

### Where is my private key?

On the machine where you created the CSR, never in the certificate email. Keep it secret and back it up; without it the certificate cannot be installed.

### What is the CA bundle or chain?

Intermediate certificates that link your certificate to a trusted root. Install them together with your certificate, or some browsers and apps show errors.

### Do I need a dedicated IP address for SSL?

No. Server Name Indication (SNI) lets many sites with their own certificates share one IP address, and every current browser supports it.

---

Source: <https://hyperdc.com/guides/products/install-ssl-certificate>\
Updated: 2026-10-09
