How to activate a Let’s Encrypt SSL certificate with ISPConfig?

Procédure

  

Service concerned: LWS VPS server
Panel concerned: ISPConfig 3
Level: beginner

An SSL certificate allows you to access your site with an address starting with https:// and encrypts communication between the site and its visitors.

ISPConfig can generate a free Let’s Encrypt certificate for a site already configured on your VPS. The certificate will then be renewed automatically, provided that the domain continues to point correctly to the server.

This help applies to VPS servers using ISPConfig.

Are you using another environment?

Before you begin

The site must already have been added in ISPConfig.

The domain name must also point to your VPS IP address. [PERSON_NAME] with www, it must also point to the server.

Do not enable Let’s Encrypt immediately after a DNS change. Wait until propagation is complete.

If the domain does not yet point to the VPS, ISPConfig will not be able to generate the certificate.

Enable Let’s Encrypt in ISPConfig

  1. Log in to your ISPConfig interface.
  2. Open the Sites (1) menu.
    How to activate a Let’s Encrypt SSL certificate with ISPConfig?
  3. In the Websites (2) section, click the relevant domain name (3).
  4. In the site settings, check the following options:
    • SSL;
    • Let’s Encrypt SSL.
      How to activate a Let’s Encrypt SSL certificate with ISPConfig?
  5. Check that the field related to the automatic subdomain matches the address you want to use:
    • choose a configuration with www if your site must be accessible with and without www;
    • do not add www if this address is not configured in your zone [ADDRESS]>
  6. Click Save.

ISPConfig then starts creating the certificate. The operation may take a few minutes.

Check that the certificate works

Open your site in a new tab using an address starting with https://, for example:

https://your-domain.com

[PERSON_NAME] configured [PERSON_NAME] www, test it separately:

https://www.your-domain.com

The certificate is correctly installed when the site opens in HTTPS without a security warning in the browser.

Installing the certificate makes HTTPS available, but it does not redirect [PERSON_NAME] http://.

To automatically force HTTPS usage, you will need to set up a script (.htaccess) or a plugin (if using a CMS) to perform the automatic redirect.

The Let’s Encrypt certificate is automatically renewed by ISPConfig. No manual intervention is required as long as the domain remains correctly configured and accessible from the VPS.

Common issues

The Let’s Encrypt option [PERSON_NAME]>

[PERSON_NAME] usually means that ISPConfig was unable to generate the certificate.

Check the following points:

  • the domain points correctly to the VPS IP address;
  • DNS propagation is complete;
  • the address with www also points to the VPS if it is enabled in ISPConfig;
  • [PERSON_NAME] IPv6 record does not direct the domain to another server.

After correcting the pointing, check SSL and Let’s Encrypt SSL again, then save.

The site works without www, but not with www

The www address probably does not point to your VPS or was not included in the site configuration.

Check the www DNS record, [PERSON_NAME] ISPConfig.

A certificate warning appears in the browser

Check that you are viewing exactly the domain name for which the certificate was created.

A certificate generated only for your-domain.com does not necessarily cover www.your-domain.com, and vice versa.

My site remains accessible over HTTP

This behavior is normal if no redirect has been configured. The certificate enables HTTPS, but does not automatically force its use.

Set up a permanent redirect from HTTP to HTTPS to send all visitors to the secure version of the site.

HTTPS works, but some resources are flagged as insecure

[PERSON_NAME] site is probably still loading images, scripts, or stylesheets with addresses starting with http://.

Replace these addresses with their https:// version or correct your application’s configuration.

Rate this article :

2.9/5 | 10 opinion

This article was useful to you ?

Article utileYes

Article non utileNo

MerciMerci ! N'hésitez pas à poser des questions sur nos documentations si vous souhaitez plus d'informations et nous aider à les améliorer.


Vous avez noté 0 étoile(s)

Similar articles

2mn reading

How to use [PERSON_NAME] with ISPConfig?

3mn reading

Diagnose and correct a 500 error on a VPS with ISPConfig

13mn reading

[PERSON_NAME] his site on a VPS server with ISP Config


Questions sur cet article

Ask the LWS team and its community a question

RGPD : Responsable LWS-Ligne Web Services. Finalité : modération et publication publique de votre question, notification éventuelle d'une réponse. Base légale : consentement (art. 6.1.a RGPD). Conservation des emails : 90 jours après notification, 12 mois maximum sans réponse. Vous pouvez exercer vos droits via notre nos CGV - section RGPD.