Configure SSL for Zabbix on Ubuntu with Apache2

Securing the Zabbix web interface with HTTPS is an important step when deploying a monitoring platform in an enterprise environment. HTTPS protects credentials, monitoring data, and administrative sessions from being transmitted unencrypted.

This guide explains how to configure SSL for Zabbix on an Ubuntu 24.04 server running Apache2. It covers the complete process, including certificate preparation, conversion of a PFX certificate, transfer to the Zabbix server, Apache configuration, and service validation.

The example uses a certificate issued by an internal enterprise Certificate Authority.

Important: Replace the example hostnames, certificate names, paths, and domain information with values from your own environment.


Prerequisites

Before starting, make sure the following requirements are met:

  • An Ubuntu 24.04 server with Zabbix installed.
  • Apache2 installed and used as the Zabbix web server.
  • Administrative access using sudo.
  • A valid certificate for the Zabbix server.
  • The certificate’s private key.
  • OpenSSL available on the administration workstation.
  • Access to the certificate password.
  • A DNS record or local host entry for the Zabbix server.

The example server uses the following hostname:

zabbixsrv01

The certificate files use the same base name:

zabbixsrv01.pfx
zabbixsrv01.pem
zabbixsrv01.key
zabbixsrv01.crt

Prepare the SSL Certificate

The certificate should be issued for the fully qualified domain name used to access Zabbix. For example:

zabbix.example.com

The certificate must contain the correct DNS name in either the Common Name or, preferably, the Subject Alternative Name field.

The source certificate is provided as a PFX file:

zabbixsrv01.pfx

A PFX file can contain:

  • The server certificate.
  • The private key.
  • The certificate chain.
  • Password protection.

Apache2 on Ubuntu normally uses separate certificate and private-key files. Therefore, the PFX file must be converted before it is installed.

Security note: The private key is sensitive. Store it only in protected locations and do not upload it to public repositories or unencrypted file shares.


Using a Subject Alternative Name for a Friendly URL

If you want to access Zabbix using a friendly, descriptive URL instead of the server hostname, you can use a Subject Alternative Name (SAN) in the certificate.

For example, instead of:

https://zabbixsrv.example.com

you might prefer:

https://zabbix.example.com

or even:

https://monitoring.example.com

Why use a SAN?

Modern browsers and many security policies no longer rely on the Common Name (CN) alone. Instead, they expect the requested hostname to be present in the Subject Alternative Name extension of the certificate.

Using a SAN allows you to:

  • Use a descriptive, service-oriented URL (e.g. zabbix, monitoring, noc).
  • Keep the underlying server hostname independent from the public URL.
  • Support multiple hostnames with a single certificate (e.g. zabbix.example.com and monitoring.example.com).
  • Meet current browser and security baseline requirements.

Requesting a certificate with a SAN

When requesting the certificate from your internal CA or public provider, specify:

  • Common Name (CN):
    The primary hostname, for example:
    zabbixsrv01.example.com
  • Subject Alternative Names (SANs):
    One or more additional DNS names, for example:
    DNS:zabbix.example.com
    DNS:monitoring.example.com

The exact process depends on your certificate authority. In a Microsoft AD CS environment, this is typically configured in the certificate template or via additional subject name attributes in the request.

tname used in the address bar, the connection will be trusted (assuming the issuing CA is trusted by the client).


Convert PFX to a Private Key

Open a terminal on the workstation where the PFX file is stored and run:

openssl pkcs12 -in "C:\Temp\zabbixsrv.pfx" -nocerts -out "C:\Temp\zabbixsrv01.pem" -nodes

OpenSSL will request the password of the PFX file.

This command exports the private key to a PEM file. The -nodes option prevents OpenSSL from encrypting the exported private key.

The resulting file is:

C:\Temp\zabbixsrv01.pem

Because the private key is not protected by a passphrase after this step, ensure that the file is handled securely.


Remove the Passphrase from the Private Key

Apache2 usually requires an unencrypted private key so that the service can restart automatically without asking for a password.

Run the following command:

openssl rsa -in "C:\Temp\zabbixsrv01.pem" -out "C:\Temp\zabbixsrv01.key"

This creates the Apache-compatible private-key file:

textC:\Temp\zabbixsrv01.key

After verifying that the new key works, securely delete temporary files that are no longer required.


Convert the PFX Certificate to CRT

Export the public certificate from the PFX file:

openssl pkcs12 -in "C:\Temp\zabbixsrv01.pfx" -clcerts -nokeys -out "C:\Temp\zabbixsrv01.crt"

This creates the certificate file:

C:\Temp\zabbixsrv01.crt

The -clcerts option exports the client or server certificate without the CA certificate chain, while -nokeys ensures that no private key is exported in this step.

Depending on the certificate authority and Apache configuration, you may also need the issuing CA or intermediate certificate chain.


Store the Certificate Files Securely

After conversion, the certificate files should be stored in a restricted administrative location.

The files should include:

zabbixsrv01.crt
zabbixsrv01.key

The original PFX file and the private key password should be protected carefully. Passwords should not be stored in the blog article, shell history, scripts, or Git repositories.


Transfer the Certificates to the Zabbix Server

Copy the certificate files to the Zabbix server. A temporary location such as the home directory of the administrative user can be used:

/home/admin/

For example, the following files should be available on the server:

/home/admin/zabbixsrv01.crt
/home/admin/zabbixsrv01.key

You can verify the files with:

ls -l /home/admin/zabbixsrv01.*

You also can use third-party tool for transfering the files to the server like WinSCP.
Make sure the private-key file is not readable by unauthorized users.


Create an Apache SSL Directory

Create a dedicated directory for the Apache SSL files:

sudo mkdir -p /etc/apache2/ssl

Restrict access to the directory:

sudo chmod 700 /etc/apache2/ssl

Linux paths are case-sensitive. Use the same directory name consistently. For example:

/etc/apache2/ssl

Copy the certificate and key files into the directory:

sudo cp /home/tgadmin/zabbixsrv01.crt /etc/apache2/ssl/
sudo cp /home/tgadmin/zabbixsrv01.key /etc/apache2/ssl/

Set appropriate permissions on the private key:

sudo chmod 600 /etc/apache2/ssl/zabbixsrv01.key

The certificate itself can normally be readable by the Apache process:

sudo chmod 644 /etc/apache2/ssl/zabbixsrv01.crt

Verify the final files:

sudo ls -l /etc/apache2/ssl/

Configure the Hostname

The Zabbix hostname must resolve to the correct server IP address. In a production environment, use DNS whenever possible.

For a temporary or local configuration, edit the hosts file:

sudo nano /etc/hosts

Add an entry similar to:

127.0.1.1    zabbix.example.com
127.0.1.1 zabbixsrv01.internal.net

Replace the IP address and hostnames with the values used in your environment.

Test name resolution:

getent hosts zabbix.example.com

The returned IP address should point to the Zabbix server.


Configure Apache2 for SSL

Open the default SSL virtual-host configuration:

sudo nano /etc/apache2/sites-available/default-ssl.conf

Configure the certificate paths in the SSL virtual host:

<VirtualHost *:443>
ServerName zabbix.example.com

SSLEngine on
SSLCertificateFile /etc/apache2/ssl/debbg0004l.crt
SSLCertificateKeyFile /etc/apache2/ssl/debbg0004l.key

DocumentRoot /usr/share/zabbix

<Directory "/usr/share/zabbix">
Options FollowSymLinks
AllowOverride None
Require all granted
</Directory>

ErrorLog ${APACHE_LOG_DIR}/zabbix_ssl_error.log
CustomLog ${APACHE_LOG_DIR}/zabbix_ssl_access.log combined
</VirtualHost>

The exact Zabbix Apache configuration can differ depending on the installed Zabbix version and package source. Avoid removing existing Zabbix-specific directives unless you know that they are no longer required.

If your certificate requires an intermediate CA certificate, configure the certificate chain according to your certificate authority’s recommendations.


Enable the Apache SSL Configuration

Enable the default SSL site:

sudo a2ensite default-ssl

Enable the Apache SSL module:

sudo a2enmod ssl

Apache may report that additional modules, such as socache_shmcb, are being enabled automatically.

Before restarting Apache, validate the configuration:

sudo apache2ctl configtest

A successful configuration test returns:

Syntax OK

Only restart Apache after the configuration test completes successfully:

sudo systemctl restart apache2

Check the service status:

sudo systemctl status apache2

If Apache is active, the SSL configuration has been loaded.


Test the Zabbix HTTPS Connection

Open the following address in a web browser:

https://zabbix.example.com

Check the following items:

  • The page loads over HTTPS.
  • The certificate matches the hostname.
  • The certificate is trusted by the client.
  • The certificate has not expired.
  • The browser does not report a hostname mismatch.
  • The Zabbix login page is displayed correctly.

You can also test the certificate from the command line:

openssl s_client -connect zabbix.example.com:443 -servername zabbix.example.com

To display only the certificate information:

echo | openssl s_client -connect zabbix.example.com:443 -servername zabbix.example.com 2>/dev/null | openssl x509 -noout -subject -issuer -dates

This displays the certificate subject, issuing authority, and validity dates.


Troubleshooting Apache SSL

Apache fails to restart

Check the configuration:

sudo apache2ctl configtest

Review the system journal:

sudo journalctl -u apache2 -xe

Also check the Apache error log:

sudo tail -f /var/log/apache2/error.log

Private key and certificate do not match

Verify the certificate modulus:

openssl x509 -noout -modulus -in /etc/apache2/ssl/debbg0004l.crt | openssl sha256

Verify the private-key modulus:

openssl rsa -noout -modulus -in /etc/apache2/ssl/debbg0004l.key | openssl sha256

The resulting hashes must be identical. If they differ, the certificate and private key belong to different certificate requests.

Permission denied

Check the permissions of the SSL directory and private key:

sudo ls -ld /etc/apache2/ssl
sudo ls -l /etc/apache2/ssl/

The Apache service must be able to read the certificate and private-key files, while the private key should remain inaccessible to regular users.

Certificate is not trusted

If the browser reports that the certificate is not trusted, check whether:

  • The issuing CA is trusted by the client.
  • The intermediate certificate is installed correctly.
  • The certificate was issued by the expected internal CA.
  • The hostname matches the certificate’s Subject Alternative Name.
  • The certificate has not expired.

The old certificate is still displayed

Restart or reload Apache:

sudo systemctl reload apache2

If the old certificate remains visible, check the following:

  • Another virtual host is listening on port 443.
  • DNS points to a different server.
  • A reverse proxy or load balancer terminates SSL.
  • The browser is displaying cached certificate information.

List Apache’s active virtual hosts:

sudo apache2ctl -S

Security Recommendations

Follow these recommendations when configuring SSL for Zabbix:

  • Use a certificate issued by a trusted internal or public CA.
  • Use a fully qualified DNS name.
  • Protect the private-key file with restrictive permissions.
  • Do not store private keys in Git repositories.
  • Remove temporary PFX, PEM, and key files after installation.
  • Renew certificates before they expire.
  • Monitor certificate expiration with Zabbix or another monitoring solution.
  • Use modern TLS settings supported by your organization.
  • Keep Ubuntu, Apache2, PHP, and Zabbix updated.
  • Restrict access to the Zabbix interface with firewall rules or a reverse proxy where appropriate.

Complete Command Overview

The following commands summarize the main installation steps on the Ubuntu server:

sudo mkdir -p /etc/apache2/ssl

sudo chmod 700 /etc/apache2/ssl

sudo cp /home/tgadmin/debbg0004l.crt /etc/apache2/ssl/
sudo cp /home/tgadmin/debbg0004l.key /etc/apache2/ssl/

sudo chmod 644 /etc/apache2/ssl/debbg0004l.crt
sudo chmod 600 /etc/apache2/ssl/debbg0004l.key

sudo nano /etc/hosts

sudo nano /etc/apache2/sites-available/default-ssl.conf

sudo apache2ctl configtest

sudo a2ensite default-ssl

sudo a2enmod ssl

sudo systemctl restart apache2

sudo systemctl status apache2

Conclusion

Configuring SSL for Zabbix on Ubuntu with Apache2 requires three main steps: preparing the certificate, installing the certificate files on the server, and configuring Apache2 to use HTTPS.

The PFX certificate must be converted into a certificate file and an unencrypted private key. After the files are copied to /etc/apache2/ssl, Apache can be configured with the correct SSLCertificateFile and SSLCertificateKeyFile directives.

Always run apache2ctl configtest before restarting Apache. This helps prevent configuration errors from causing unnecessary service interruptions.

Once the configuration is complete, access Zabbix through its HTTPS URL and verify the certificate, hostname, trust chain, and validity period.

Schreibe einen Kommentar