You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linode Debian8服务器配置ISP Config:通配符SSL证书与强制HTTPS方法

Hey there! Let's work through your two ISPConfig questions since you're running Debian 8 on Linode with that standard ISPConfig directory structure (/var/www/html/example.com/public_html). I'll break this down clearly for you:

1. Configuring a Wildcard SSL Certificate in ISPConfig

First, ditch those self-signed certificates—they’re the root cause of your browser/client warnings. Grab a trusted wildcard SSL certificate (Let’s Encrypt offers free, reliable ones that work perfectly here). Once you have your cert files ready, follow these steps:

  • Log into your ISPConfig control panel, navigate to your example.com site’s edit page.
  • Switch to the SSL tab, then check the "SSL" box to enable SSL support.
  • Paste your certificate files into the corresponding fields:
    • SSL Certificate: Use your full certificate chain file (usually fullchain.pem for Let’s Encrypt) — this includes your main cert plus intermediate CA certs, which eliminates trust warnings.
    • SSL Key: Paste your private key file (typically privkey.pem).
    • SSL Bundle: If your provider gave you a separate CA bundle, paste it here. For Let’s Encrypt, fullchain.pem already includes this, so you can leave this field empty.
  • To apply the wildcard cert to all subdomains, update your site’s domain field in ISPConfig to: example.com, *.example.com (comma-separated).
  • Save your changes. ISPConfig will auto-update your web server (Apache/Nginx) config and restart the service. Be sure to delete any old self-signed certs from the server to avoid conflicts.
2. Forcing All Connections to Use HTTPS

You’ve got a few reliable options here, depending on your web server:

Option 1: Use ISPConfig’s Built-in Redirect Tool (Easiest)

No manual config edits needed:

  • Go back to your site’s edit page, switch to the Redirect tab.
  • Set Type to Permanent (301) (this tells browsers/search engines to remember the HTTPS version).
  • In Source URL, enter / to catch all paths.
  • In Target URL, enter https://%{HTTP_HOST}%{REQUEST_URI} — this preserves the original page path during redirect.
  • Save, and ISPConfig handles the rest.

Option 2: Use .htaccess (For Apache)

If you prefer Apache rewrite rules, create/edit the .htaccess file in your site’s public directory (/var/www/html/example.com/public_html) with this code:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Make sure mod_rewrite is enabled on Apache:

a2enmod rewrite
systemctl restart apache2

Option 3: Edit Nginx Config (For Nginx)

Find the port 80 server block for your domain, and replace its content with a permanent redirect:

server {
    listen 80;
    server_name example.com *.example.com;
    return 301 https://$host$request_uri;
}

Restart Nginx to apply changes:

systemctl restart nginx

Quick Reminder About Self-Signed Cert Warnings

Once you replace self-signed certs with a trusted wildcard SSL (like Let’s Encrypt’s), browsers and email clients will stop showing those annoying trust alerts. Self-signed certs are only for testing—never use them in production!

内容的提问来源于stack exchange,提问作者The Harmonic Rainbow

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:33:24