> ## Documentation Index
> Fetch the complete documentation index at: https://help.enrolweb.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Installing SSL

> Install your issued SSL certificate on EnrolWeb hosting, cPanel, or a custom server, and configure HTTPS redirects to secure every request.

Once your SSL certificate is issued, install it on your server so browsers connect over HTTPS. This guide covers installation in cPanel, on shared hosting, and on custom VPS servers.

## Files you'll receive

Your Certificate Authority sends three main files:

* **Certificate** (`.crt`) — your primary SSL certificate
* **CA bundle / intermediate** (`.ca-bundle` or `.crt`) — chain of trust
* **Private key** (`.key`) — the key you generated during CSR creation

## Install SSL in cPanel

<Steps>
  <Step title="Open SSL/TLS Manager">
    In cPanel, open **SSL/TLS** > **Manage SSL sites**.
  </Step>

  <Step title="Select your domain">
    Choose the domain you want to secure from the dropdown.
  </Step>

  <Step title="Paste your certificate">
    Paste the contents of the `.crt` file into the Certificate field.
  </Step>

  <Step title="Paste your private key">
    Paste your private key into the Private Key field.
  </Step>

  <Step title="Paste the CA bundle">
    Paste the CA bundle into the Certificate Authority Bundle field.
  </Step>

  <Step title="Install">
    Click **Install Certificate**. cPanel confirms when installation is complete.
  </Step>
</Steps>

## Install on a custom server

### Nginx

```nginx theme={null}
server {
    listen 443 ssl;
    server_name yourdomain.com;

    ssl_certificate /etc/ssl/yourdomain.crt;
    ssl_certificate_key /etc/ssl/yourdomain.key;
    ssl_trusted_certificate /etc/ssl/ca-bundle.crt;
}
```

Reload Nginx: `systemctl reload nginx`

### Apache

```apache theme={null}
<VirtualHost *:443>
    ServerName yourdomain.com
    SSLEngine on
    SSLCertificateFile /etc/ssl/yourdomain.crt
    SSLCertificateKeyFile /etc/ssl/yourdomain.key
    SSLCertificateChainFile /etc/ssl/ca-bundle.crt
</VirtualHost>
```

Restart Apache: `systemctl restart apache2` or `systemctl restart httpd`

## Force HTTPS

After installation, redirect all HTTP traffic to HTTPS.

### In cPanel

<Steps>
  <Step title="Open Domains">
    In cPanel, open **Domains** and find your domain.
  </Step>

  <Step title="Toggle Force HTTPS Redirect">
    Enable the **Force HTTPS Redirect** toggle.
  </Step>
</Steps>

### With .htaccess (Apache)

```apache theme={null}
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```

### In Nginx

```nginx theme={null}
server {
    listen 80;
    server_name yourdomain.com;
    return 301 https://$host$request_uri;
}
```

## Verify installation

<CardGroup cols={2}>
  <Card title="Browser check" icon="globe">
    Visit `https://yourdomain.com` and confirm the padlock icon.
  </Card>

  <Card title="SSL Labs test" icon="chart-line">
    Run [ssllabs.com/ssltest](https://www.ssllabs.com/ssltest) for a full grade.
  </Card>

  <Card title="Mixed content" icon="triangle-exclamation">
    Fix any HTTP resources loaded on HTTPS pages.
  </Card>

  <Card title="Renewal reminder" icon="calendar">
    Set a calendar reminder before expiration.
  </Card>
</CardGroup>

<Warning>
  Never share your private key. If it's exposed, \[reissue your certificate]\(/SSL & Website Security/contact-2-2-3-2) with a new key.
</Warning>

Install trouble? Contact [support@enrolweb.com](mailto:support@enrolweb.com).
