Install SSL on HestiaCP.
Use a custom SSL certificate for an existing Hestia web domain.
Before you begin: use an issued production certificate and its matching private key. Back up the current configuration. Staging certificates are not publicly trusted.
1Edit the web domain
Open Web in HestiaCP, select your domain, and choose Edit. Enable SSL support. For a manually generated certificate, do not select Hestia's separate automatic Let's Encrypt issuance option.
2Add certificate, key and authority
Paste cert.pem into SSL Certificate, privkey.pem into SSL Key, and chain.pem into SSL Certificate Authority / Intermediate. Labels vary by Hestia version. Do not omit the chain.
3Save and verify
Save the domain settings and check the HTTPS endpoint. Enable HTTPS redirection after successful verification. Imported certificates must be renewed manually unless you move to Hestia's built-in ACME automation.
Confirm the connection.
Check the installed certificate and chain, then keep an eye on the expiry date.
Open SSL Checker