CapRover, established by a team of developers in 2017, has rapidly become a go-to solution for containerized application deployment and management. With its user-friendly interface and powerful features, CapRover simplifies tasks such as Docker container deployment, SSL certificate provisioning, and automated scaling. With a growing user base exceeding 20,000 developers globally, CapRover empowers users to effortlessly manage their cloud infrastructure, focusing more on their applications and less on administrative overhead.
- Step 1: Generating a CSR and Private Key
- Step 2: Order and Configure the SSL Certificate
- Step 3: Upload the SSL Certificate Files to your Server
- Step 4: Test the SSL Certificate
Step 1. Generating a CSR and Private Key
CSR: A Key Component for SSL Certificate Issuance
A CSR (Certificate Signing Request) is a pivotal element in obtaining SSL certificates, containing
crucial data such as the server's public key and domain information. When a client seeks to secure their
website with SSL, they generate a CSR, which is then submitted to a Certificate Authority (CA) for
validation. Effective CSR utilization is paramount for SEO, as it facilitates the issuance of trusted
SSL certificates, enhancing website security and search engine rankings through encrypted connections
and improved user trust.
Navigate to SSLTrust's CSR Generator and generate your CSR and Private Key.
Note:- Save the generated Private Key and CSR on your device. This might come in handy if you want to re-do the configuration.
Step 2. Order and Configure the SSL Certificate
The following step in the installation process is to order and configure SSL Certificate. We recommend SSLTrust because of our exceptional Customer Service, Money Back guarantee and SSL Installation Service.
1: Once you've added the SSL Certificate into your cart, you can now click on Checkout to complete the process.
Fill in your account details
Choose your preferred mode of payment and click on checkout.
2: After you have purchased the SSL Certificate, you can start the configuration process.
This can be started by going into your SSLTrust account and managing your recent purchase.
Head over to the SSLTrust Dashboard and under Services, select My Services.
You should be able to see your purchased certificate and order status, now click on Manage
This will take you to the Product Details of your SSL Certificate. Click on start configuration to do the configuration yourself or you can provide the URL below to the appropriate person to complete the configuration for you.
3: Copy and paste the previously generated CSR (Certificate Signing Request) which should include:-
-----BEGIN CERTIFICATE REQUEST----- -----END CERTIFICATE REQUEST-----
Then, click on Verify CSR.
If the CSR details match the inputs you've entered before, you can now proceed or else generate a new CSR with proper details.
Select the Server Type and click on Next Step>
4: Fill in your contact information
If you have a technical contact managing the certificate for you, please enter their details.
They will also have permission to manage the Certificate and will be sent renewal reminders.
To obtain a business SSL certificate, you will need to provide your business details, including your correct address, phone number, and legal entity name. The Certificate Authority will verify the accuracy of this information. If there are any mistakes, it may cause delays in the process.
Then, click on Next Step
5: The next step in this process is Domain Control Validation (DCV).
DCV, or Domain Control Validation, is a crucial step in SSL certificate issuance. It verifies that the entity requesting the certificate has control over the specific domain by utilizing methods like email verification, file uploads, or DNS changes. This process ensures the legitimacy of SSL certificates and enhances online security.
Select the method that is easiest for you. Having an email address with the domain name will be the quickest.
You will be sent an email containing a link which when clicked upon should validate your domain name.
In HTTP/HTTPS File Validation Method, you can create a folder in the specified and directory, paste in the contents and your domain should be validated.
The final method to validate your domain name would be CNAME Validation. Basically you have to create a CNAME record in your DNS Settings to validate your domain name and then click on the Check DNS Record button to verify DNS changes.
After a few seconds or minutes depending on your DNS propagation speed, the CNAME record should be verified.
The configuration should be a success. Click on the button below to access the validation manager.
6: Your certificate should have now been issued if you completed all the above steps correctly.
If not, click on Domain Control Validation, and re-submit whatever method you chose for validation.
Upon completing domain validation using the chosen method, your SSL certificate will be issued. If you have ordered a Business SSL, you will need to wait for the Certificate Authority to verify your business address and phone number. If the validation process has not been completed or you have not received your certificate after a certain period of time, please reach out to the support team to check on the status of your certificate.
Step 3. Upload the SSL Certificate Files to your Server
Once your SSL certificate has been issued, you will receive an email with the certificate directly from the Certificate Authority. Alternatively, you can download the certificate from the SSLTrust Portal, which presents the certificate in a convenient, easy-to-use format.
Again, head over to the SSLTrust Dashboard and click on your certificate:-
1: Click on Collect/Download Certificate-
Go to the first column and click on copy to clipboard
2: Login to your account on CapRover and navigate to Settings in the left menu.
3: Click on "Load Default and Edit" under the Nginx Configuration. Scroll down to the Caprover config file.
4: Login to your server via SSH as root via Putty
5: Run the following commands and Paste in your copied primary certificate
sudo mkdir /etc/certs sudo nano /etc/certs/certificate.crt
6: Copy and paste your Private Key
sudo nano /etc/certs/private.key
7: Furthermore, head back to the certificate collection page and click on copy to clipboard on the Intermediate certificate.
8: Paste the intermediate certificate just after the main certificate to form a chain such as.
-----BEGIN CERTIFICATE----- MAIN CERTIFICATE DATA -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- INTERMEDICATE CERTIFICATE DATA -----END CERTIFICATE-----
9: Make the following changes in the Nginx Default Configuration at /etc/nginx/conf.d/captain-root.conf
LOOK FOR:-
ssl_certificate <%-s.crtPath%>; ssl_certificate_key <%-s.keyPath%>;
CHANGE TO:-
ssl_certificate <%/etc/certs/certificate.crt%>; ssl_certificate_key <%/etc/certs/private.key%>;
10: Finally, click on Save and Restart.
Now, navigate to https:// yourdomain.com to view your secure website.
Step 4. Test the SSL Certificate
SSL Labs, now called Qualys SSL Labs, is a web service providing tools to analyze and test the SSL/TLS configurations of web servers. Its SSL Server Test assesses various security aspects, assigning a grade based on the server's overall security posture. This tool is widely used by administrators and security professionals to ensure secure server configurations and identify vulnerabilities.
We recommend you use this tool to check the install has been completed successfully: www.ssllabs.com/ssltest/
You may need to get your web developer, or update your website yourself, to make sure all files use https:// and all links to your site and within your website use https://
If you require any assistance with your SSL Installation please contact our friendly support team.