Files you need
yourdomain.crt: your certificateca-bundle.crt: the intermediate chainyourdomain.key: the private key from your CSR
Nginx
Nginx wants your certificate and the chain in one file, your certificate first:
cat yourdomain.crt ca-bundle.crt > /etc/ssl/yourdomain/fullchain.pem cp yourdomain.key /etc/ssl/yourdomain/privkey.pem chmod 600 /etc/ssl/yourdomain/privkey.pem
server {
listen 443 ssl http2;
server_name yourdomain.pk www.yourdomain.pk;
ssl_certificate /etc/ssl/yourdomain/fullchain.pem;
ssl_certificate_key /etc/ssl/yourdomain/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;
add_header Strict-Transport-Security "max-age=31536000" always;
}
server {
listen 80;
server_name yourdomain.pk www.yourdomain.pk;
return 301 https://yourdomain.pk$request_uri;
}
Test and reload: nginx -t && systemctl reload nginx
Apache 2.4
<VirtualHost *:443>
ServerName yourdomain.pk
ServerAlias www.yourdomain.pk
SSLEngine on
SSLCertificateFile /etc/ssl/yourdomain/yourdomain.crt
SSLCertificateKeyFile /etc/ssl/yourdomain/yourdomain.key
SSLCertificateChainFile /etc/ssl/yourdomain/ca-bundle.crt
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
</VirtualHost>
Enable and reload: a2enmod ssl && apachectl configtest && systemctl reload apache2
Test
Run the SSL checker. It confirms the chain order and the expiry. From the terminal you can also run openssl s_client -connect yourdomain.pk:443 -servername yourdomain.pk and look for Verify return code: 0 (ok).
Written by the SSLWalay team, Karachi. Last reviewed October 2026. Prices quoted are SSLWalay PKR prices at the time of review and can change; the product pages always show the live price.