Knowledge Base


How to Install and Bind a Sectigo SSL Certificate on Lite Speed?
Product: Sectigo SSL Certificate
Platform: Lite Speed Web Server
Purpose:
Use this guide for step-by-step instructions on installing and binding a Sectigo SSL certificate on a Lite Speed Web Server.
Overview:
This guide provides the step-by-step process for installing a Sectigo SSL certificate on a Lite Speed Web Server to enable secure HTTPS connections and improve website security.
Audience:
System administrators and web hosting professionals managing Lite Speed servers.
Scope:
This procedure covers downloading SSL files, configuring Lite Speed listeners, and enabling SSL protocols for secure communication.
Prerequisites
-
1.Before you begin, ensure you have the following:
-
2.Administrator access to the Lite Speed Web-Admin console
-
3.Sectigo SSL certificate bundle (primary certificate, CA bundle, and private key) downloaded
-
4.OpenLiteSpeed or Lite Speed installed and running
-
5.Access to the server directory where SSL files are stored
Step-by-Step Installation Guide
-
Step 1: Obtain Your SSL Certificate Files:
Download the Sectigo SSL certificate bundle, including the primary certificate, CA bundle, and private key.
-
Step 2: Access Lite Speed Admin Console: Log in to the Lite Speed Web-Admin console (usually at https://yourdomain.com:7080).
-
Step 3: Navigate to Configuration > Listeners > Click “+” icon
-
Step 4: Configure a new Listener
Use the following Address Settings to configure the newly created Listener:
-
Listener Name – Enter the internal friendly name for your Listener.
-
IP Address – Select Any from the dropdown unless you want to bind the Listener to a particular machine. In that case, enter the unique IP-port combination.
-
Port – Most HTTPS connections are managed through port 443 by default. However, if you have other Listeners operating on that port, this may cause an issue and require you to use another port such as 8443.
-
Secure – Select Yes.
-
Notes – Add any internal notes that will help you distinguish the Listener in the future.
-
Click Save.
-
Step 5: Configure SSL for Your Listener: Select the listener (e.g., Default). Go to the SSL tab and click Edit.
-
Step 6: Configure the file paths
-
Use the following instructions to properly configure your Certificate file paths as shown below:
-
Private Key File – This is the path to your private key that was previously saved on your directory during the generation process via OpenSSL.
-
Certificate File – This is the path to your server certificate that the CA sent you. You should already have this saved locally or in your server directory. Only complete one of the two options below to successfully install the intermediate certificates:
-
CA Certificate Path – This is the path to the intermediate certificate “file” that the CA sent you.
-
CA Certificate File – This is the path to the “directory” holding the intermediate certificates that the CA sent you.
-
Click Save.
-
Step 7: Configure SSL Protocol
Once you’re back on the SSL tab under your Listener, click the Edit button on the SSL Protocol section.
-
Step 8: Select “Protocol Version” and save
-
Step 9: Select Virtual Host
-
Step 10: Enter the Domains
Once you have the appropriate Virtual Host selected, enter all the Domains that connect to your vhost(s).This tells OpenLiteSpeed where to send traffic this listener picks up – and click Save.
Note 1: If you have multiple domains in the certificate that connect to the vhost, use a comma “,” to separate the additional domains.
Note 2: If you have one vhost and configured the server to disregard other vhosts, you can enter an asterisk “*” as the domain.
-
Step 11: Apply Changes and Restart: Save your changes and restart LiteSpeed to apply the SSL configuration.
-
Verification:
After installation, visit SSL Labs (https://www.ssllabs.com/ssltest/) to check certificate validity, intermediate chain, and overall SSL health.
Troubleshooting Tips
-
Ensure the private key matches the certificate.
-
Verify CA bundle is correctly uploaded to avoid chain issues.
-
Restart LiteSpeed after making SSL changes.
-
Check firewall settings if SSL port (443) is blocked.
Related Articles:
Tags:
Need help?
Need help making a purchase? Contact us today to get your certificate issued right away.
Live chat
Click the button below or click "Chat with an Expert" to start chatting with us now!