How to Install and Configure TLS/SSL on AlmaLinux 9

Estimated reading: 7 minutes 415 views

To install and configure TLS/SSL on AlmaLinux 9, you need to set up a web server (such as Apache or Nginx) and install an SSL/TLS certificate to enable secure HTTPS connections. The following guide provides a detailed, step-by-step process using Apache (httpd) as the web server, as it is widely used on AlmaLinux. If you prefer Nginx or have specific requirements, please clarify, and I can tailor the instructions accordingly.

Prerequisites

  • AlmaLinux 9 system: Ensure the system is fully updated using sudo dnf update -y.
  • Root or sudo privileges: Necessary for installing packages and editing configuration files.
  • Domain name: A fully qualified domain name (FQDN) pointing to your server’s public IP address via DNS (for production environments).

Setting Up FQDN

Run the following command to set up the FQDN of your AlmaLinux machine. In this case, the server will have the fqdn greencloudvps.example.net.

hostnamectl set-hostname greencloudvps.example.net
echo "nameserver 8.8.8.8" | sudo tee -a /etc/resolv.conf

Now open the /etc/hosts file using the following nano editor command.

nano /etc/hosts

Insert the following configuration and be sure to change the IP address, FQDN, and hostname.

Your_IP   greencloudvps.example.net

Save the file and exit the editor when finished.

Lastly, run the following command to verify the FQDN of your system and ensure that it’s pointed to the proper local IP address.

hostname -f
ping -c3 greencloudvps.example.net
  • Web server: Apache or Nginx installed and running.
  • Firewall: Ports 80 (HTTP) and 443 (HTTPS) must be open to allow traffic.
  • Network access: The server must be accessible from the internet if using Let’s Encrypt.

Step 1: Install Apache Web Server

If Apache is not already installed, follow these steps to set it up.

    1. Install Apache:
      dnf install httpd -y
      mv /etc/httpd/conf.d/welcome.conf /etc/httpd/conf.d/welcome.conf.org  # rename or remove welcome page

      This installs the Apache web server package.

    2. Start and enable Apache:
      systemctl start httpd
      systemctl enable httpd

      This ensures Apache starts automatically on system boot.

    3. Verify Apache is running:
      systemctl status httpd

      Check the output to confirm the service is active and running.

      Add firewall rules:

      firewall-cmd --permanent --add-service=http
      firewall-cmd --permanent --add-service=https
      firewall-cmd --reload
    4. Configure httpd. Replace the Server name with your own environment.
      [root@Greencloud ~]# nano /etc/httpd/conf/httpd.conf
      # line 91 : change to admin's email address
      ServerAdmin [email protected]
      # line 100 : change to your server's name
      ServerName www.greencloudvps.example.net:80
      # line 149 : change (remove [Indexes])
      Options FollowSymLinks
      # line 156 : change
      AllowOverride All
      # line 169 : add file name that it can access only with directory's name
      DirectoryIndex index.html index.php index.cgi
      # add follows to the end
      # server's response header
      ServerTokens Prod
      [root@Greencloud ~]# systemctl enable --now httpd
    5. Test Apache: Access http://your_server_ip or http://your_domain  in a browser to confirm Apache is serving content (you should see the default Apache page).

Create an HTML test page and access it from any client computer with a web browser. It’s OK if the following page is shown.

[root@Greencloud ~]# nano /var/www/html/index.html
<html>
<body>
<div style="width: 100%; font-size: 40px; font-weight: bold; text-align: center;">
Hello Greencloud
</div>
</body>
</html>

Step 2: Install mod_ssl for Apache

The mod_ssl module enables SSL/TLS support for Apache.

  1. Install mod_ssl:
    dnf install mod_ssl -y

    This package provides SSL/TLS functionality and creates a default SSL configuration file at /etc/httpd/conf.d/ssl.conf.

  2. Verify installation: Apache automatically configures It to listen on port 443 (HTTPS). You can check this in /etc/httpd/conf.d/ssl.conf.

Step 3: Obtain an SSL/TLS Certificate

To enable HTTPS, you need an SSL/TLS certificate. This guide uses Let’s Encrypt, a free and automated Certificate Authority (CA), with Certbot for simplicity. If you have a commercial certificate, skip to Step 4 for manual configuration.

Install Certbot

  1. Install the EPEL repository (required for Certbot):
    dnf install epel-release -y
  2. Install Certbot and the Apache plugin:
    dnf install certbot python3-certbot-apache -y

Request a Let’s Encrypt Certificate

  1. Run Certbot to obtain and install the certificate:
    certbot certonly --webroot -w /var/www/html -d greencloudvps.example.net
    • Replace yourdomain.com with your actual domain name.
    • Include www.yourdomain.com if you want the certificate to cover the www subdomain.
    • Follow the interactive prompts to:
      • Provide an email address for renewal and security notices.
      • Agree to the Let’s Encrypt terms of service.
      • Choose whether to redirect HTTP traffic to HTTPS (recommended).
  2. Verify certificate files: Certbot stores certificates in /etc/letsencrypt/live/yourdomain.com/. Key files include:
    • fullchain.pem: The server certificate and intermediate chain.
    • privkey.pem: The private key.
  3. Automatic Apache configuration: Certbot modifies Apache’s configuration to use the certificate and enables HTTPS. It may also create a new virtual host file (e.g., /etc/httpd/conf.d/yourdomain.com-le-ssl.conf) for the HTTPS configuration.

Step 4 – Verify the Configuration

Test the Apache configuration syntax:

apachectl configtest

If you do not intend to use the default SSL virtual host (e.g., you manage certificates per-domain manually):

  1. dit /etc/httpd/conf.d/ssl.conf:

    nano /etc/httpd/conf.d/ssl.conf
  2. Locate the lines around line 85 (or search for SSLCertificateFile) and comment them out:

    # SSLCertificateFile /etc/pki/tls/certs/localhost.crt
    # SSLCertificateKeyFile /etc/pki/tls/private/localhost.key

The default /etc/httpd/conf.d/ssl.conf file is a sample/template and is not required for production use when managing certificates with Certbot or custom virtual hosts.

  • Rename (or remove) the file to prevent it from being loaded:

    mv /etc/httpd/conf.d/ssl.conf /etc/httpd/conf.d/ssl.conf.disabled

    (Using .disabled or .bak is safer than deletion.)

If the output reports “Syntax OK”, restart Apache to apply changes:

systemctl restart httpd
Visit your site in a browser using https://example.com. You should observe a secure padlock icon.

For an independent evaluation of the TLS setup, use an online scanner such as SSL Labs.

Step 5 – Certificate Renewal

Perform a dry-run test of the renewal process:
certbot renew --dry-run
Certificates are valid for 90 days; automatic renewal occurs approximately 30 days before expiration.

Manual TLS Configuration (Advanced – When Not Using Certbot –apache)

If certificates are obtained separately (e.g., via DNS-01 challenge or another CA), place them in a secure directory (commonly /etc/letsencrypt/live/example.com/) and configure Apache manually.

Example virtual host configuration (create or edit a file in /etc/httpd/conf.d/greencloudvps.example.net.conf):

<VirtualHost *:443>
    ServerName example.com
    ServerAlias www.example.com
    DocumentRoot /var/www/html

    SSLEngine on
    SSLCertificateFile      /etc/letsencrypt/live/example.com/fullchain.pem
    SSLCertificateKeyFile   /etc/letsencrypt/live/example.com/privkey.pem

    # Recommended modern security settings (2025–2026 standards)
    SSLProtocol             all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
    SSLCipherSuite          ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256
    SSLHonorCipherOrder     on

    # Enable HSTS (after initial testing)
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
</VirtualHost>
After editing, test and restart:
apachectl configtest
systemctl restart httpd
This procedure aligns with current best practices for AlmaLinux 9 and Apache as of 2026. Should you encounter specific errors during execution or require guidance on advanced features (e.g., OCSP stapling, ECC keys, or multi-domain SAN certificates), please provide additional details for targeted assistance.
Share this Doc

How to Install and Configure TLS/SSL on AlmaLinux 9

Or copy link

CONTENTS