1. Home
  2. Knowledge Base
  3. SSL Certificate Guides
  4. Install SSL Certificate
  5. NGINX
  6. How to Install Your SSL Certificate in Nginx

How to Install Your SSL Certificate in Nginx

To install a certificate in Nginx, a ‘Certificate Bundle’ must be created. To accomplish this, each certificate (SSL Cert, Intermediate Cert, and Root Cert) must be in the PEM format.

  1.  Open each certificate in a plain text editor

  2. Create a new document in a plain text editor

  3. Copy and paste the contents of each certificate into the new file

The order should be:

  • Your GlobalSign SSL Certificate
  • GlobalSign Intermediate Certificate
  • GlobalSign Root Certificate

Your completed file should be in this format:

#Your GlobalSign SSL Certificate#

#GlobalSign Intermediate Certificate#

#GlobalSign Root Certificate#

  1. Save this ‘Certificate Bundle’ as a .crt

  2. Upload the Certificate Bundle & private key to a directory on the Nginx server

  3. Edit the Nginx virtual hosts file

  4. Open the Nginx virtual host file for the website you are securing. If you need your site to be accessible through both secure (https) and non-secure (http) connections, you will need a server module for each type of connection

  5. Make a copy of the existing non-secure server module and paste it below the original

  6. Add the lines shown below:

server { 

listen 443;  

ssl on;  

ssl_certificate /etc/ssl/your_domain.crt;  

ssl_certificate_key /etc/ssl/your_domain.key;  

server_name your.domain.com;  


access_log /var/log/nginx/nginx.vhost.access.log;  

error_log /var/log/nginx/nginx.vhost.error.log; 


location / {  

root /home/www/public_html/yourdomain.com/public/;  

index index.html;  


Note: Make sure you adjust the file names to match your certificate files:

  • ssl_certificate should be your primary certificate combined with the root & intermediate certificate bundle that you made in the previous step (e.g. your_domain.crt)
  • ssl_certificate_key should be the key file generated when you created the CSR

Now, restart Nginx:

sudo  systemctl nginx reload or sudo service nginx reload


Get in touch with us for a non-binding quote

We will contact you as soon as possible.

* Please use a work email address to register

Was this article helpful?