ISPConfig is an open source hosting control panel widely used on Debian and Ubuntu based servers. It is ideal for professional hosting environments with its multi-server support and flexible configuration options. In this guide, we explain in detail SSL installation, CSR creation and Let's Encrypt integration in the ISPConfig 3 panel.
1. Creating CSR
Via ISPConfig Panel
- Login to ISPConfig administration panel
- Switch to "Sites" tab
- Select the relevant website
- Click on the "SSL" tab
- Select "Create Certificate" from the "SSL Action" dropdown
- Fill in the required information:
- SSL Country: TR
- SSL State: Istanbul
- SSL Locality: Istanbul
- SSL Organization: Company Name
- SSL Organization Unit: IT
- SSL Domain: www.example.com
- Click the "Save" button
- The CSR will appear in the "SSL Request" field
Creating CSR from Command Line
openssl req -new -newkey rsa:2048 -nodes \
-keyout /var/www/clients/client1/web1/ssl/example.com.key\
-out /var/www/clients/client1/web1/ssl/example.com.csr
2. Installing an SSL Certificate
- ISPConfig → "Sites" → Select website → "SSL" tab
- Select "Save Certificate" from the "SSL Action" dropdown
- Fill in the following fields:
- SSL Key: Paste private key
- SSL Certificate: CRT certificate content
- SSL Bundle: CA Bundle / Intermediate certificate
- Click the "Save" button
- Select "On" from "SSL" dropdown
- Save again
3. Let's Encrypt Integration
ISPConfig 3.1+ offers built-in Let's Encrypt support:
- Go to "SSL" tab in website settings
- Tick the "Let's Encrypt" checkbox
- Set "SSL" dropdown to "On"
- Click the "Save" button
- ISPConfig will automatically obtain and install the Let's Encrypt certificate
certbot certificates4. Apache/Nginx SSL Configuration
Apache Vhost (managed by ISPConfig)
# Auto-generated file: /etc/apache2/sites-available/example.com.vhost
<VirtualHost *:443>
ServerName example.com
ServerAlias www.example.com
SSLEngine on
SSLCertificateFile /var/www/clients/client1/web1/ssl/example.com.crt
SSLCertificateKeyFile /var/www/clients/client1/web1/ssl/example.com.key
SSLCertificateChainFile /var/www/clients/client1/web1/ssl/example.com.bundle
</VirtualHost>
5. HTTPS Redirect
- "Redirect" tab in ISPConfig site settings
- "Redirect Type": R,L (301 permanent)
- "Redirect Path": https://www.example.com
- Or select "www to non-www + https" from the "SEO Redirect" section
6. Common Errors and Solutions
| Error | Solution |
|---|---|
| Let's Encrypt: Challenge failed | Make sure the .well-known/acme-challenge directory is accessible |
| SSL certificate not activated in Apache | Enable Apache SSL module: a2enmod ssl && systemctl restart apache2 |
| Error in Vhost configuration | Test the configuration with apache2ctl configtest |
Frequently Asked Questions
Does ISPConfig multi-server support SSL?
Yes, in ISPConfig's multi-server architecture, each web server can perform independent SSL management. The panel server distributes the certificate information to the relevant web server.
How do I back up my SSL certificate in ISPConfig?
SSL files are stored in the /var/www/clients/clientX/webX/ssl/ directory. Include this directory in your backup plan.