Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section Web Server
  • Search

StartSSL Certificate on Domain

Questions regarding the Web Server
Apache + Nginx, Nginx + PHP5-FPM
Post Reply
  • Print view
Advanced search
10 posts • Page 1 of 1
badams
Posts: 7
Joined: Wed Aug 05, 2015 3:43 pm

StartSSL Certificate on Domain
  • Quote

Post by badams » Mon Feb 22, 2016 6:30 am

I dont know why Im struggling so much with this.
Ive installed SSL certificates before on other servers, but it seems Vesta just wants to fight me on this one.

I generated a CSR in VestaCP, took that over to StartSSL, did the domain verification, etc. etc. etc.

Got the zip file from StartSSL which contained several zip files within it.
ApacheServer.zip
IISServer.zip
NgixServer.zip
OtherServer.zip

Im assuming the ApacheServer.zip is the one I need, since (to my understanding... correct me if im wrong) apache is whats used for the web hosting of domains.
Inside ApacheServer.zip, I have:
1_root_bundle.crt
2_domain.crt

I put the text from domain.crt into SSL Certificate in VestaCP.
I put the RSA Private key that VestaCP generated earlier into the SSL Key section in VestaCP.
If I hit save at this point, I get an error: Certificate Authority Not Found.

So Im assuming the bundle.crt needs to go into the Certificate Authority section. So I do the same thing, paste the contents of bundle.cry into the authority section, then I get the error: ssl certificate key pair is not valid

Why am I struggling so much with this?? What am I doing wrong here?!
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: StartSSL Certificate on Domain
  • Quote

Post by dpeca » Mon Feb 22, 2016 11:46 am

Take NginxServer.zip, because Vesta is running on nginx on port 8083 :)

Put cert file instead of /usr/local/vesta/ssl/certificate.crt
Put key file instead of /usr/local/vesta/ssl/certificate.key
And then run:

Code: Select all

service vesta restart
Also restart exim4 and dovecot.
Top

badams
Posts: 7
Joined: Wed Aug 05, 2015 3:43 pm

Re: StartSSL Certificate on Domain
  • Quote

Post by badams » Mon Feb 22, 2016 2:26 pm

dpeca wrote:Take NginxServer.zip, because Vesta is running on nginx on port 8083 :)

Put cert file instead of /usr/local/vesta/ssl/certificate.crt
Put key file instead of /usr/local/vesta/ssl/certificate.key
And then run:

Code: Select all

service vesta restart
Also restart exim4 and dovecot.
I think you are misunderstanding what I am trying to do. I am not trying to put the ssl certificate on the local VestaCP. I'm trying to add an ssl certificate to an actual domain (on port 80)
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: StartSSL Certificate on Domain
  • Quote

Post by dpeca » Mon Feb 22, 2016 3:49 pm

Oh, sorry then, please ignore my post :(
Yes, I misunderstood you.
Top

tjebbeke
Collaborator
Posts: 783
Joined: Mon May 11, 2015 8:43 am
Contact:
Contact tjebbeke
Website

Os: CentOS 6x
Web: apache + nginx
Re: StartSSL Certificate on Domain
  • Quote

Post by tjebbeke » Mon Feb 22, 2016 7:03 pm

In your vestaCP:
SSL Certificate: content of otherServer.zip -> 2_yourdomain.com.crt
SSL Key: your RSA PRIVATE KEY
SSL Certificate Authority / Intermediate: otherServer.zip -> 1_Intermediate.crt
Top

Wamphyri
Posts: 3
Joined: Sat Apr 30, 2016 9:29 am

Re: StartSSL Certificate on Domain
  • Quote

Post by Wamphyri » Sat Apr 30, 2016 9:51 am

I've been trying to get startssl to work on one of my sites, i keep getting Error: SSL intermediate chain is not valid. i have tried the way tjebbeke said, either i get a ssl key error or the chain error. Would cloudflaire stop the ssl from working properly?
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: StartSSL Certificate on Domain
  • Quote

Post by skurudo » Wed May 04, 2016 1:05 pm

Wamphyri wrote:I've been trying to get startssl to work on one of my sites, i keep getting Error: SSL intermediate chain is not valid. i have tried the way tjebbeke said, either i get a ssl key error or the chain error. Would cloudflaire stop the ssl from working properly?
StartSSL intermediate chain
https://www.startssl.com/root

cloudflare intermediate chain
https://support.cloudflare.com/hc/en-us ... Origin-CA-
Top

Wamphyri
Posts: 3
Joined: Sat Apr 30, 2016 9:29 am

Re: StartSSL Certificate on Domain
  • Quote

Post by Wamphyri » Sun May 22, 2016 3:23 pm

i ended up figuring it out after a lot of trial and error. now i'm just working one some error issues with my email lol
Top

mehargags
Support team
Posts: 1096
Joined: Sat Sep 06, 2014 9:58 pm
Contact:
Contact mehargags
Website Skype

Os: Debian 8x
Web: apache + nginx
Re: StartSSL Certificate on Domain
  • Quote

Post by mehargags » Sun May 22, 2016 7:18 pm

Wamphyri wrote:i ended up figuring it out after a lot of trial and error. now i'm just working one some error issues with my email lol
When you seek answers in the forum, have the courtesy to share "solutions" if you reach one... to help others seeking the same.
Top

spell
Posts: 4
Joined: Thu Jan 07, 2016 1:02 pm

Re: StartSSL Certificate on Domain
  • Quote

Post by spell » Sun Aug 21, 2016 8:16 pm

Hi huys.

I've experienced the samу issue and after a long way googling i've found out that the fieds have to be filed in with this info

1 your_doimain.crt

2 ssl private key NOT ENCRYPTED!!!

3
root crt
intermediate crt
OR
contents of "1_root_bundle" from ApacheServer archive

AT STEP 2
you need to get decrypted key out of your encrypted one. So you go to https://startssl.com/ click on a "Tool Box" tab then down on the left "Decrypt Private Key" put the contents of your "yourname.key" file in "Enter Private Key and Password" field and press Decrypt. Copy the contents of new opened field. Voilà :-)

Have a great day!
Top


Post Reply
  • Print view

10 posts • Page 1 of 1

Return to “Web Server”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password