Configure Apache HTTPS with a Self-Signed Certificate for Testing
Step‑by‑step guide to enable HTTPS on Apache 2.4 using mod_ssl and a self‑signed certificate for local testing, including key generation, virtual host configuration, permission hardening, and verification with openssl s_client.
14 Aug 2026, 01:13 UTC

Desired outcome
Apache HTTP Server listens on port 443 and serves content over HTTPS, presenting a self‑signed certificate to clients. This setup is intended for local development, staging, or internal services where a public CA is not required.
Prerequisites
- Apache HTTP Server 2.4 or newer installed and running.
- OpenSSL library and command‑line tools available (usually provided by the
opensslpackage). - Root or sudo privileges to edit configuration files, manage the
mod_sslmodule, and restart the service. - Firewall or security group allowing inbound traffic on TCP port 443.
Procedure
1. Generate a private key and self‑signed certificate
Run the following commands on the server where Apache is installed. Adjust the subject fields (-subj) to match your test domain or IP.
sudo mkdir -p /etc/ssl/localcerts
sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 \
-keyout /etc/ssl/localcerts/apache-selfsigned.key \
-out /etc/ssl/localcerts/apache-selfsigned.crt \
-subj "/C=US/ST=State/L=City/O=Organization/OU=IT/CN=localhost"Permissions: The private key must be readable only by the Apache user (typically www-data on Debian/Ubuntu, apache on RHEL/CentOS). Set restrictive permissions:
sudo chown root:www-data /etc/ssl/localcerts/apache-selfsigned.key
sudo chmod 640 /etc/ssl/localcerts/apache-selfsigned.key
sudo chown root:root /etc/ssl/localcerts/apache-selfsigned.crt
sudo chmod 644 /etc/ssl/localcerts/apache-selfsigned.crt2. Enable the SSL module
On Debian‑based systems use a2enmod; on RHEL‑based systems ensure mod_ssl is loaded in /etc/httpd/conf.modules.d/00-ssl.conf.
sudo a2enmod ssl
sudo systemctl reload apache23. Create an HTTPS virtual host
Add a <VirtualHost *:443> block to your site configuration. On Debian/Ubuntu this is typically a file under /etc/apache2/sites-available/; on RHEL/CentOS use /etc/httpd/conf.d/ssl.conf or a dedicated file in /etc/httpd/conf.d/.
<VirtualHost *:443>
ServerName localhost
DocumentRoot /var/www/html
SSLEngine on
SSLCertificateFile /etc/ssl/localcerts/apache-selfsigned.crt
SSLCertificateKeyFile /etc/ssl/localcerts/apache-selfsigned.key
# Optional: improve security posture for testing
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
SSLCipherSuite HIGH:!aNULL:!MD5:!3DES
</VirtualHost>Ensure Listen 443 is present in ports.conf (Debian) or httpd.conf (RHEL). The SSL module usually adds it automatically.
4. Enable the site and reload Apache
sudo a2ensite your-ssl-site.conf # Debian/Ubuntu
sudo systemctl reload apache2On RHEL/CentOS:
sudo systemctl reload httpdExpected checks
Verify the TLS handshake
Run the following on the server (or from a client with network access) to confirm the certificate is presented and the handshake completes:
openssl s_client -connect localhost:443 -servername localhost -showcertsLook for Verify return code: 18 (self signed certificate) and the certificate subject matching the one you generated. A successful handshake shows CONNECTED and the certificate chain.
Inspect Apache logs
Check the error log for SSL startup messages:
sudo tail -n 50 /var/log/apache2/error.log # Debian/Ubuntu
sudo tail -n 50 /var/log/httpd/error_log # RHEL/CentOSYou should see lines indicating mod_ssl loaded and the virtual host started without errors.
Browser test
Navigate to https://localhost (or the server’s IP). The browser will display a security warning because the certificate is self‑signed. Accept the warning to confirm content is served over HTTPS.
Limitations and cautions
- Browser warnings: Self‑signed certificates are not trusted by any browser or OS by default. They are suitable only for testing, internal tools, or environments where you can manually trust the certificate.
- Key permissions: If the private key is readable by users other than the Apache process, Apache may refuse to start or log a permission error. Verify with
ls -l /etc/ssl/localcerts/. - Cipher configuration: The example disables older protocols (SSLv3, TLS 1.0, 1.1). Adjust
SSLProtocolandSSLCipherSuiteif you need compatibility with legacy clients. - Certificate lifetime: The example uses 365 days. For longer test periods increase
-days; for production you must obtain a CA‑signed certificate.
Recovery options
If Apache fails to start after configuration changes:
- Run
sudo apache2ctl configtest(Debian/Ubuntu) orsudo httpd -t(RHEL/CentOS) to spot syntax errors. - Check that the certificate and key paths exist and match the
SSLCertificateFileandSSLCertificateKeyFiledirectives. - Ensure the
Listen 443directive is not duplicated or conflicting with another service. - Revert the virtual host file, disable the site (
a2dissite), and reload Apache to restore the previous state.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.