Enabling SSL On Apache
Updated 2026-09-23: moved the intermediate cert to SSLCertificateChainFile, the directive meant for it.
This is a quick overview of the process of adding an SSL certificate to apache (for next time…):
Generate your private key and CSR with:
openssl req -new -newkey rsa:2048 -nodes -keyout yourdomain.key -out yourdomain.csr- Request your certificate
- Save requested certificate onto server in a .crt file
- Download the intermediate cert bundle from your CA
- Make your site file in
/etc/apache2/sites-enabled/look like this:
<VirtualHost *:443>
SSLEngine On
SSLCertificateFile /home/youruser/yourdomain.crt
SSLCertificateKeyFile /home/youruser/yourdomain.key
SSLCertificateChainFile /var/www/verisign.crt
ServerName www.yourdomain.com
DocumentRoot /var/www/yourdomain
An explanation of each of those certificates:
SSLCertificateFile- This is the certificate you received after your request.SSLCertificateKeyFile- This is the private key you generated in step 1.SSLCertificateChainFile- This is the intermediate cert you downloaded from your CA. (On Apache 2.4.8+, append it to theSSLCertificateFileinstead.)