How do I enable the mod_ssl module in Apache?
Before you can install an SSL/TLS certificate on Apache, you must enable mod_ssl — the Apache module that adds SSL and TLS encryption support. This guide covers Linux (CentOS/RHEL and Debian/Ubuntu) and Windows.
Prerequisites
Before you begin, make sure you have:
Apache 2.x installed and running
rootaccess or a user withsudopermissions (Linux), or administrator access (Windows)
Enable the mod_ssl module on Linux
CentOS/RHEL
Check whether
mod_sslis already enabled.sudo httpd -M | grep ssl_moduleIf the output contains
ssl_module, the module is already enabled — skip to install an SSL certificate.Install the module.
Run the command for your OS version:
CentOS/RHEL 8 and later
sudo dnf install -y mod_sslCentOS/RHEL 7 and earlier
sudo yum install -y mod_sslThe installation automatically creates
/etc/httpd/conf.d/ssl.conf— the configuration file where Apache reads your certificate path, private key path, and TLS settings.mod_sslis now enabled and ready for certificate installation.
Debian/Ubuntu
Check whether
mod_sslis already enabled.sudo apache2ctl -M | grep ssl_moduleIf the output contains
ssl_module, the module is already enabled — skip to install an SSL certificate.Enable the module.
sudo a2enmod sslmod_sslis now enabled and ready for certificate installation.
Enable the mod_ssl module on Windows
This guide uses Apache 2.4.x installed in C:\Apache24 as an example. Adjust the file paths to match your actual installation directory.
Check whether
mod_ssl.sois present. Open theC:\Apache24\modulesdirectory. Ifmod_ssl.sois there, the module is available — proceed to step 2. If not, download and reinstall Apache from the Apache official website.Enable the module in
httpd.conf. OpenC:\Apache24\conf\httpd.confin a text editor with administrator privileges. Find the following two lines and remove the leading#to uncomment them:LoadModule socache_shmcb_module modules/mod_socache_shmcb.so LoadModule ssl_module modules/mod_ssl.soSave and close the file.
mod_sslis now enabled.
Troubleshooting
a2enmod: command not found or Module ssl does not exist (Debian/Ubuntu)
This means your Apache installation might be missing core files. Back up all your Apache configuration files first, then run:
# Update the package list
sudo apt update
# Force reinstall to restore missing core files
sudo apt install --reinstall apache2After reinstalling, enable the module again and verify:
sudo a2enmod ssl
sudo apache2ctl -M | grep ssl_moduleIf the output contains ssl_module, the module is enabled successfully.