How do I enable the mod_ssl module in Apache?

Updated at:

Before you can install an SSL/TLS certificate on Apache, you must enable mod_ssl — the Apache module that adds SSL and TLS encryption support. This guide covers Linux (CentOS/RHEL and Debian/Ubuntu) and Windows.

Prerequisites

Before you begin, make sure you have:

  • Apache 2.x installed and running

  • root access or a user with sudo permissions (Linux), or administrator access (Windows)

Enable the mod_ssl module on Linux

CentOS/RHEL

  1. Check whether mod_ssl is already enabled.

    sudo httpd -M | grep ssl_module

    If the output contains ssl_module, the module is already enabled — skip to install an SSL certificate.

  2. Install the module.

    Run the command for your OS version:

    CentOS/RHEL 8 and later

    sudo dnf install -y mod_ssl

    CentOS/RHEL 7 and earlier

    sudo yum install -y mod_ssl

    The installation automatically creates /etc/httpd/conf.d/ssl.conf — the configuration file where Apache reads your certificate path, private key path, and TLS settings.

    mod_ssl is now enabled and ready for certificate installation.

Debian/Ubuntu

  1. Check whether mod_ssl is already enabled.

    sudo apache2ctl -M | grep ssl_module

    If the output contains ssl_module, the module is already enabled — skip to install an SSL certificate.

  2. Enable the module.

    sudo a2enmod ssl

    mod_ssl is now enabled and ready for certificate installation.

Enable the mod_ssl module on Windows

Note

This guide uses Apache 2.4.x installed in C:\Apache24 as an example. Adjust the file paths to match your actual installation directory.

  1. Check whether mod_ssl.so is present. Open the C:\Apache24\modules directory. If mod_ssl.so is there, the module is available — proceed to step 2. If not, download and reinstall Apache from the Apache official website.

  2. Enable the module in httpd.conf. Open C:\Apache24\conf\httpd.conf in a text editor with administrator privileges. Find the following two lines and remove the leading # to uncomment them:

    LoadModule socache_shmcb_module modules/mod_socache_shmcb.so
    LoadModule ssl_module modules/mod_ssl.so

    Save and close the file. mod_ssl is now enabled.

Troubleshooting

a2enmod: command not found or Module ssl does not exist (Debian/Ubuntu)

This means your Apache installation might be missing core files. Back up all your Apache configuration files first, then run:

# Update the package list
sudo apt update

# Force reinstall to restore missing core files
sudo apt install --reinstall apache2

After reinstalling, enable the module again and verify:

sudo a2enmod ssl
sudo apache2ctl -M | grep ssl_module

If the output contains ssl_module, the module is enabled successfully.

What's next