CloudPanel is a lightweight and modern hosting control panel. It offers high performance with its structure built on Nginx and supports application types such as PHP, Node.js, Python. In this guide, we explain in detail how to install an SSL certificate on CloudPanel, Let's Encrypt configuration and CSR creation.
1. Automatic SSL with Let's Encrypt
The fastest way to set up SSL on CloudPanel is to use Let's Encrypt:
- Login to CloudPanel management panel (https://server-ip:8443)
- From the left menu, go to "Sites" section
- Click on the relevant site's settings
- Switch to "SSL/TLS" tab
- Select "New Let's Encrypt Certificate" from the "Actions" dropdown
- Confirm the domain name
- Click the "Create and Install" button
- The certificate is installed shortly; Let's Encrypt certificates are valid for 90 days and are renewed automatically before they expire
2. Creating CSR
Generating CSR with SSH
# Creating CSR on CloudPanel server
openssl req -new -newkey rsa:2048 -nodes \
-keyout /etc/nginx/ssl-certificates/example.com.key\
-out /etc/nginx/ssl-certificates/example.com.csr \
-subj "/C=TR/ST=Istanbul/L=Istanbul/O=Company/CN=example.com"
# ECC (Elliptic Curve) CSR generation (faster)
openssl ecparam -genkey -name prime256v1 -out example.com.key
openssl req -new -key example.com.key -out example.com.csr \
-subj "/C=TR/ST=Istanbul/L=Istanbul/O=Company/CN=example.com"
3. Paid SSL Certificate Installation
Via CloudPanel Panel
- "Sites" → Related site → "SSL/TLS"
- "Actions" → "Import SSL Certificate"
- Install the following files:
- Certificate: SSL certificate (CRT)
- Private Key: Private key
- Certificate Chain: CA Bundle / Intermediate
- Click the "Import and Install" button
Manual Nginx Configuration
# Copying certificate files
cp example.com.crt /etc/nginx/ssl-certificates/
cp example.com.key /etc/nginx/ssl-certificates/
cat ca-bundle.crt >> /etc/nginx/ssl-certificates/example.com.crt
# Nginx configuration control
nginx -t
# Nginx reload
systemctl reload nginx
4. HTTPS Redirect
CloudPanel performs automatic HTTPS redirection when SSL is active. For manual configuration:
At Nginx Level
# In the Site's Nginx Vhost settings
server {
listen 80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}
5. SSL Security Optimization
To increase SSL security in CloudPanel Nginx configuration:
# Strong SSL configuration
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256;
ssl_prefer_server_ciphers off;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 1d;
ssl_session_tickets off;
# OCSP Stapping
ssl_stapling on;
ssl_stapling_verify on;
#HSTS
add_header Strict-Transport-Security "max-age=63072000" always;
6. Common Errors and Solutions
| Error | Solution |
|---|---|
| Let's Encrypt failed | Check the DNS A record. Make sure port 80/443 is open. |
| SSL certificate format error | Make sure it is in PEM format. If it is DER format, convert: openssl x509 -inform DER -in cert.der -out cert.pem |
| Nginx restart error | Test the configuration with nginx -t. Examine the error message. |
| Certificate chain missing | Add the CA Bundle file to the end of the certificate file: cat ca-bundle.crt >> cert.crt |
Frequently Asked Questions
Which operating systems does CloudPanel support?
CloudPanel runs on Debian 11/12 and Ubuntu 22.04/24.04. Supports Nginx, MariaDB/MySQL and the latest PHP versions.
Can I use wildcard SSL in CloudPanel?
Let's Encrypt wildcard SSL requires DNS verification. You can easily install the paid wildcard SSL certificate with the import option.
How is CloudPanel SSL performance?
CloudPanel's Nginx-based structure offers good SSL/TLS performance thanks to TLS 1.3 and HTTP/2 support.