Virtualmin is an open source hosting control panel based on Webmin and is widely used on Linux servers. It offers powerful tools for SSL certificate management. In this guide, we cover SSL installation, CSR creation and Let's Encrypt configuration on Virtualmin/Webmin step by step.
1. SSL Setup from Virtualmin
Step 1: Creating CSR
- Login to Virtualmin panel (https://server-ip:10000)
- Select the relevant domain from the left menu
- "Server Configuration" → "SSL Certificate"
- Click on the "Create Signing Request" tab
- Fill in the information:
- Organisation: Company name
- Organization Unit: IT Department
- City/State/Country: Location information
- Email: Admin email
- Click the "Create Now" button
- The CSR text will appear on the screen — copy it
Step 2: Installing SSL Certificate
- "Install Certificate" tab on the "SSL Certificate" page
- Use one of the options:
- "Paste text below" — Paste the certificate content
- "Upload certificate file" — Upload the CRT file
- Add the CA Bundle file in the same way
- Click the "Install Now" button
2. Let's Encrypt Module
Virtualmin offers built-in Let's Encrypt support:
- Select Domain → "Server Configuration" → "SSL Certificate"
- Click the "Let's Encrypt" tab
- Click the "Request Certificate" button
- The certificate will be automatically installed and Apache/Nginx configured
Automatic Renewal
# Virtualmin's Let's Encrypt refresh cron job
# Automatically created under /etc/cron.d/
# Manual refresh
virtualmin generate-letsencrypt-cert --domain example.com --renew
# Renewal for all domains
virtualmin generate-letsencrypt-cert --all-domains --renew
3. Webmin Server SSL Configuration
To set up SSL on the Webmin panel itself:
- Webmin → "Webmin" menu → "Webmin Configuration"
- Click "SSL Encryption"
- Specify certificate files:
- Private key file: /etc/webmin/miniserv.pem
- Certificate file: Certificate file path
- Additional certificate files: CA Bundle path
- Click the "Save" button
- Restart Webmin
4. HTTPS Redirect
- Virtualmin → Select Domain → "Server Configuration" → "Website Options"
- Set "Redirect all requests to SSL site?" to Yes
- Click the "Save" button
5. Common Errors and Solutions
| Error | Solution |
|---|---|
| Let's Encrypt rate limit exceeded | Wait a week or use staging server: --staging |
| Apache SSL module is not active | a2enmod ssl && systemctl restart apache2 |
| Port 443 is used in another service | ss -tlnp | check with grep 443 |
| Certificate and key do not match | Use the key generated with the same CSR. Check: openssl x509 -noout -modulus -in cert.crt | md5sum |
Frequently Asked Questions
Is SSL automatically installed on every domain in Virtualmin?
If you enable the "Request Let's Encrypt certificate at creation time" option in Virtualmin settings, SSL will be automatically received for each newly added domain.
How to install SSL on Webmin's own panel?
You can configure the panel HTTPS certificate from the Webmin Configuration → SSL Encryption section. You can also get an automatic certificate with Let's Encrypt.