Linode Debian8服务器配置ISP Config:通配符SSL证书与强制HTTPS方法
Hey there! Let's work through your two ISPConfig questions since you're running Debian 8 on Linode with that standard ISPConfig directory structure (/var/www/html/example.com/public_html). I'll break this down clearly for you:
First, ditch those self-signed certificates—they’re the root cause of your browser/client warnings. Grab a trusted wildcard SSL certificate (Let’s Encrypt offers free, reliable ones that work perfectly here). Once you have your cert files ready, follow these steps:
- Log into your ISPConfig control panel, navigate to your
example.comsite’s edit page. - Switch to the SSL tab, then check the "SSL" box to enable SSL support.
- Paste your certificate files into the corresponding fields:
- SSL Certificate: Use your full certificate chain file (usually
fullchain.pemfor Let’s Encrypt) — this includes your main cert plus intermediate CA certs, which eliminates trust warnings. - SSL Key: Paste your private key file (typically
privkey.pem). - SSL Bundle: If your provider gave you a separate CA bundle, paste it here. For Let’s Encrypt,
fullchain.pemalready includes this, so you can leave this field empty.
- SSL Certificate: Use your full certificate chain file (usually
- To apply the wildcard cert to all subdomains, update your site’s domain field in ISPConfig to:
example.com, *.example.com(comma-separated). - Save your changes. ISPConfig will auto-update your web server (Apache/Nginx) config and restart the service. Be sure to delete any old self-signed certs from the server to avoid conflicts.
You’ve got a few reliable options here, depending on your web server:
Option 1: Use ISPConfig’s Built-in Redirect Tool (Easiest)
No manual config edits needed:
- Go back to your site’s edit page, switch to the Redirect tab.
- Set Type to
Permanent (301)(this tells browsers/search engines to remember the HTTPS version). - In Source URL, enter
/to catch all paths. - In Target URL, enter
https://%{HTTP_HOST}%{REQUEST_URI}— this preserves the original page path during redirect. - Save, and ISPConfig handles the rest.
Option 2: Use .htaccess (For Apache)
If you prefer Apache rewrite rules, create/edit the .htaccess file in your site’s public directory (/var/www/html/example.com/public_html) with this code:
RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Make sure mod_rewrite is enabled on Apache:
a2enmod rewrite systemctl restart apache2
Option 3: Edit Nginx Config (For Nginx)
Find the port 80 server block for your domain, and replace its content with a permanent redirect:
server { listen 80; server_name example.com *.example.com; return 301 https://$host$request_uri; }
Restart Nginx to apply changes:
systemctl restart nginx
Quick Reminder About Self-Signed Cert Warnings
Once you replace self-signed certs with a trusted wildcard SSL (like Let’s Encrypt’s), browsers and email clients will stop showing those annoying trust alerts. Self-signed certs are only for testing—never use them in production!
内容的提问来源于stack exchange,提问作者The Harmonic Rainbow

