HestiaCP is a modern and actively developed fork of VestaCP. It stands out with its lightweight structure, strong security features and easy use. In this guide, we explain step by step how to install an SSL certificate on HestiaCP, Let's Encrypt configuration and CSR creation.
1. Quick SSL Setup with Let's Encrypt
HestiaCP's easiest SSL installation method is let's Encrypt:
- Login to HestiaCP panel (https://server-ip:8083)
- Go to "WEB" section
- Click the Edit icon next to the relevant domain
- Scroll down to find the "SSL Support" section
- Check "Enable SSL"
- Check "Lets Encrypt Support"
- Click the "Save" button
- The SSL certificate will be installed in a few seconds
2. CSR Generation (For Paid SSL)
Generating CSR with SSH
# Creating CSR on HestiaCP server
openssl req -new -newkey rsa:2048 -nodes \
-keyout /home/admin/conf/web/ssl.example.com.key\
-out /home/admin/conf/web/ssl.example.com.csr\
-subj "/C=TR/ST=Istanbul/L=Istanbul/O=Company/CN=example.com"
With Hestia CLI
# HestiaCP command line tools
v-generate-ssl-cert example.com admin@example.com TR Istanbul Istanbul "Company Name" IT
3. Paid SSL Certificate Installation
Via Panel
- HestiaCP → "WEB" → Edit domain
- Check "Enable SSL"
- Upload the following files or paste their contents:
- SSL Certificate: CRT file
- SSL Key: Private key file
- SSL Certificate Authority / Intermediate: CA Bundle
- Click the "Save" button
From Command Line
# Copying SSL files
cp example.com.crt /home/admin/conf/web/ssl.example.com.crt
cp example.com.key /home/admin/conf/web/ssl.example.com.key
cp ca-bundle.crt /home/admin/conf/web/ssl.example.com.ca
# Introducing SSL to HestiaCP
v-add-web-domain-ssl admin example.com /home/admin/conf/web/
# Restart the web server
v-restart-web
4. HTTPS Redirect
Via HestiaCP Panel
- On the domain editing page, check the "Enable automatic HTTPS redirect" option
- Click the "Save" button
Nginx in Proxy Mode
# /home/admin/conf/web/nginx.example.com.conf_custom
if ($scheme != "https") {
return 301 https://$host$request_uri;
}
5. Common Errors and Solutions
| Error | Solution |
|---|---|
| Let's Encrypt: Error creating certificate | Check DNS redirection. Confirm access to Port 80. |
| Cannot find SSL certificate | Check file paths. v-list-web-domain admin example.com |
| Nginx configuration error | test with nginx -t, restart with v-restart-web |
| Mixed Content | Update all HTTP resources to HTTPS |
Frequently Asked Questions
How is HestiaCP different from VestaCP?
HestiaCP is an actively developed fork of VestaCP. It offers better security, modern PHP support, advanced SSL management and regular updates.
Does HestiaCP require separate SSL for the mail server?
HestiaCP can also perform automatic SSL configuration for mail services. You can activate hostname SSL with the v-add-letsencrypt-host command.