How to Install an SSL Certificate? Step-by-Step Guide
· Guide
SSL certificate installation follows a clear sequence of steps that, once understood, are straightforward to execute.
1. Generate a CSR and Private Key
Use OpenSSL on your server: openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.csr. Keep the private key secure — losing it means the certificate won't work.
2. Submit the CSR to a CA
Send the CSR content to a trusted certificate authority. Choose DV, OV, or EV based on your validation needs.
3. Complete Validation
DV: Prove domain ownership via DNS TXT record or HTTP file (minutes). OV/EV: CA verifies organizational identity (1–7 business days).
4. Install the Certificate
Load the cert and intermediate chain on your server. Nginx uses ssl_certificate and ssl_certificate_key. Apache uses SSLCertificateFile, SSLCertificateKeyFile, and SSLCertificateChainFile. IIS uses the Certificate Manager import wizard.
5. Enable HTTPS Redirect
Redirect all HTTP traffic to HTTPS with a 301 redirect. For Nginx: return 301 https://$host$request_uri;
6. Verify
Test with SSL Labs (ssllabs.com/ssltest) and aim for an A+ rating.
Visit the PekiSSL product page to find the right certificate for your needs.