Articles in this section

How to secure Plesk mail server with an SSL certificate (Let's Encrypt / other certificate authorities)

Plesk for Windows Plesk for Linux ext: le kb: auxiliary

Applicable to:

  • Plesk for Linux
  • Plesk for Windows

Question

How to secure Plesk mail server with an SSL certificate from Let's Encrypt or other certificate authorities?

Answer

Note: After configuring an SSL certificate for Plesk mail server, use the domain name from this SSL certificate, when connecting to the Plesk mail server. For details, see this KB article.

Alternatively, secure mail server with an SSL certificate for each domain separately.

Securing a Plesk mail server with a free Let's Encrypt certificate

 

  1. Log in to Plesk.
  2. Once installed, go to Tools & Settings > SSL/TLS Certificates (under Security).



     

  3. Click Let's Encrypt.

    Note: If the Let's Encrypt extension is not installed, install it from Plesk Extensions catalog.


    Screenshot_2019-03-26_SSL_TLS_Certificates_-_Plesk_Onyx_17_8_11.png
     

  4. Make sure the Domain name and Email address fields contain a valid information:

    • Domain name will be used as an incoming and outgoing mail server when setting up an email account in a mail client. This domain must point to your Plesk server.
    • Email address will be used to receive important notifications and warnings.


    Screenshot_2019-03-26_Secure_Plesk_With_a_Let_s_Encrypt_Certificate_-_Plesk_Onyx_17_8_11.png
     

  5. Click Install. At this stage, an SSL certificate from Let’s Encrypt is generated and set to secure Plesk on port 8443 automatically. This certificate will be auto-renewed every 90 days.
  6. Now, to secure a Plesk mail server, click [Change] next to Certificate for securing mail.


    Screenshot_2019-03-26_SSL_TLS_Certificates_-_Plesk_Onyx_17_8_11_1_.png
     

  7. In the drop-down list, select Lets Encrypt certificate (server pool) and click OK. Here is the final look:


    Screenshot_2019-03-26_SSL_TLS_Certificates_-_Plesk_Onyx_17_8_11_1_.png
     

Securing a Plesk mail server with an SSL certificate from other certificate authorities
  1. Log in to Plesk.
  2. Go to Tools & Settings and click SSL/TLS Certificates.



     

  3. On the SSL/TLS Certificates page, add your certificate:

    Warning: Make sure to include the CA certificate in the certificate chain to avoid errors when connecting with the mail clients.

    Note: If you are experiencing issues with a certificate installation, contact your certificate seller and ask for instruction for Plesk.

    • If an SSL certificate is stored in a single *.crt file:

      Click Browse... to select a certificate file. Then click Upload Certificate.


      Screenshot_2019-01-21_SSL_TLS_Certificates_-_Plesk_Onyx_17_8_11_1_.png
       

    • If an SSL certificate is stored in the form of *.key and *.crt files:

      Click Add under List of certificates in server pool and scroll down to the Upload the certificate files section and upload these files. If both the certificate and the private key parts of your certificate are contained in a *.pem file (you can check it by opening the *.pem file in any text editor), just upload it twice, both as the private key and the certificate. Click Upload Certificate once finished.


      Screenshot_2019-03-26_Add_SSL_TLS_Certificate_-_Plesk_Onyx_17_8_11.png
       

    • If an SSL certificate is stored as a text:

      Click Add under List of certificates in server pool and scroll down to the Upload the certificate as text section. There, paste the certificate and the private key parts into the corresponding fields. Click Upload Certificate when you have finished.


      certtext.PNG
       

  4. Click [Change] next to Certificate for securing mail > select an uploaded certificate > click OK. Now mail server is secured with an SSL certificate.


    Screenshot_2019-01-21_SSL_TLS_Certificates_-_Plesk_Onyx_17_8_11_1___1_.png
     

Was this article helpful?

Comments

1 comment
Date Votes
  • Hello,

    my Plesk Server repeatedly failed to update the certificate used for E-Mail (Postfix and Dovecot). Am I the only one? Are there any workarounds?

    0

Please sign in to leave a comment.