Ask a Question

Solution ID : SO14921

Last Modified : 06/04/2018

Install SSL Web Server Certificate on CPanel Mail Server

Problem

How do I install a SSL Web Server certificate on Cpanel Mail server

Solution

To install your Thawte SSL Web Server Certificate on a CPanel Mail Server, perform the following steps:
 
Step1. Download your certificate together with the intermediate certificate required.
 
1. You will receive an email when your certificate is issued.
2. Download the Thawte Certificate with the solution: SO13187
3. Copy and Paste the  Thawte certificate in the X509 format to Notepad and save as a cert.pem extension.
4. Download the Thawte Intermediate CA for SSL Web Server certificate: AR1384 and save this using Notepad as well and save as intermediate.pem
 
 
Step2. Install your certificate 
 
First you need to import the Thawte root certificate  into your server. You can obtain the SSL Web Server certificate root certificate by following the instructions in the following solution:  SO4362

1. Copy the Thawte root certificate into a text editor such as notepad and save as root.pem.

2. Create a new file (yourcert.pem) consisting of your private key and your certificate file: 
-----BEGIN RSA PRIVATE KEY-----

[encoded key]

-----END RSA PRIVATE KEY-----

[empty line]

-----BEGIN CERTIFICATE-----

[encoded certificate]

-----END CERTIFICATE-----

[empty line] 
3. Then save the file as yourcert.pem in the /etc/ssl/certs/ directory.

4. Copy the root.pem file to the /etc/ssl/certs/ directory.
 
5. Copy the intermediate.pem file to the /etc/ssl/certs/ directory.

6. When you are setting up the SSL support you will need to access the stunnel configuration file which will probably be available at etc/stunnel/default/stunnel.conf .

7. Open the stunnel.conf and locate the following directives (they may be commented out by #). It may be necessary to add the above directives if they are not present.
 
verify=3
 
CAfile=/etc/ssl/certs/root.pem
CAfile=/etc/ssl/certs/intermediate.pem 
cert=/etc/ssl/certs/yourcert.pem
 
 
8. Restart your web / mail service for the installation to be completed. In some instances, it may be necessary to physically restart the actual machine.