What is an SSL certificate?
SSL makes a website safe, so the address starts with https://. A certificate is like an ID card for your site. It comes with a secret private key. The key proves the certificate is yours. You need both to move a certificate. There is often a third file, called the chain or CA bundle. It links your certificate to the company that issued it.
Files you need
| File | Common name |
|---|---|
| Certificate | yourdomain.crt |
| Private key | yourdomain.key |
| Chain (CA bundle) | ca-bundle.crt |
The names and paths on your server may differ. Look in your Apache config for lines starting with SSLCertificateFile, SSLCertificateKeyFile and SSLCertificateChainFile.
Steps
- On the old server, find the file paths.
grep -ri "SSLCertificate" /etc/httpd /etc/apache2 2>/dev/null
This searches the Apache config for the file paths.
- Copy the files to the new server using SCP. SCP is a secure way to copy files over SSH.
scp yourdomain.crt yourdomain.key ca-bundle.crt root@NEW_SERVER_IP:/root/
This sends the three files to the new server's /root folder.
- On the new server, move the files to a safe folder.
mkdir -p /etc/ssl/yourdomain
mv /root/yourdomain.* /root/ca-bundle.crt /etc/ssl/yourdomain/
chmod 600 /etc/ssl/yourdomain/yourdomain.key
This stores them and makes the key readable only by its owner.
- Edit the Apache virtual host for your site. A virtual host is the block of settings for one website.
- Add or update these lines inside the SSL block.
SSLEngine on
SSLCertificateFile /etc/ssl/yourdomain/yourdomain.crt
SSLCertificateKeyFile /etc/ssl/yourdomain/yourdomain.key
SSLCertificateChainFile /etc/ssl/yourdomain/ca-bundle.crt
These tell Apache where the files are.
- Test the config.
apachectl configtest
This should print Syntax OK.
- Restart Apache.
systemctl restart httpd
This applies the change. On Debian and Ubuntu, use apache2.
Check it
Open your site with https://. Click the padlock to see the certificate details. If you see an error about the key not matching, the wrong key was copied.
