Install Namecheap SSL on Nginx: Combine CRT and CA-Bundle

by Fahim

When you download an SSL cert from Namecheap (or directly from Sectigo), you get a zip archive with your domain CRT and a CA-bundle file. If you point Nginx straight at that domain CRT without merging the intermediate certificates, desktop Chrome might load your site fine from its local cache, while mobile Safari, Android, and curl immediately throw untrusted certificate warnings.

Nginx won’t fetch missing intermediate certificates on its own. You have to combine your primary cert and the CA-bundle into a single chained file. Here is how to concatenate those files in the exact sequence Nginx expects, verify the chain with OpenSSL, and wire up your server block without breaking production.

Terminal screen showing OpenSSL certificate chain verification for Nginx SSL setup
Terminal screen showing OpenSSL certificate chain verification for Nginx SSL setup

What Namecheap Sends You in the SSL Zip File

Once your SSL validation passes (either via DNS CNAME or HTTP file upload), Namecheap sends over a zip file or gives you a download button in their dashboard. When you unzip it, you usually see two files:

  • your_domain_name.crt: Your primary server certificate, issued specifically to your domain or subdomain.
  • your_domain_name.ca-bundle: The intermediate and root certs that bridge trust between your cert and a recognized root authority like Sectigo or Comodo.

Older archives sometimes included four separate files: your_domain.crt, SectigoRSADomainValidationSecureServerCA.crt, USERTrustRSAAddTrustCA.crt, and AddTrustExternalCARoot.crt. Modern Namecheap downloads pack those intermediate layers into a single .ca-bundle file so you don’t have to guess the order of three loose certs.

Generate the Private Key and CSR (If Starting Fresh)

If you already have the private key from when you generated your CSR, skip this step. But if you’re starting from scratch or reissuing, generate a clean 2048-bit RSA key and CSR directly on your server via OpenSSL:

openssl req -new -newkey rsa:2048 -nodes  -keyout /etc/ssl/certs/example_com.key  -out /etc/ssl/certs/example_com.csr

OpenSSL will prompt for your Country, State, Locality, Organization Name, and Common Name. For Common Name, enter your exact domain or subdomain (like example.com or app.example.com). If you run multiple services on subdomains, check out our guide on how to point a Namecheap subdomain to a separate server.

Lock down permissions on your private key immediately so other system users can’t read it:

sudo chmod 600 /etc/ssl/certs/example_com.key

Combine CRT and CA-Bundle in the Exact Right Order

Nginx’s ssl_certificate directive expects a chained bundle where your server certificate sits at the very top, followed immediately by the intermediate certificates. If you invert this order, Nginx will start up fine, but every client will abort the TLS handshake because the first cert sent across the wire isn’t your domain cert.

Upload your_domain_name.crt and your_domain_name.ca-bundle to /etc/ssl/certs/ on your server. Then merge them into a single chained file with cat:

cd /etc/ssl/certs # Combine domain CRT first, CA-bundle second
cat example_com.crt example_com.ca-bundle > example_com_chained.crt

If Namecheap gave you three individual intermediate files instead of a single bundle, concatenate them in descending order—from domain cert down to the root:

cat example_com.crt  SectigoRSADomainValidationSecureServerCA.crt  USERTrustRSAAddTrustCA.crt  AddTrustExternalCARoot.crt > example_com_chained.crt

Always open the resulting example_com_chained.crt in an editor to inspect the boundary lines. There must be a clean newline separating the end of your cert and the start of the next one:

-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----

If you see -----END CERTIFICATE----------BEGIN CERTIFICATE----- glued together on a single line, add a newline between them. That missing linebreak is one of the most common reasons Nginx throws an SSL_CTX_use_certificate_chain_file parse error on reload.

Verify the Certificate Chain and Match the Private Key

Before touching your Nginx configuration, verify two things on the CLI: that your combined certificate actually matches your private key, and that the intermediate chain validates cleanly.

Compare the MD5 hashes of the modulus for both your key and the chained cert. They must match word-for-word:

openssl x509 -noout -modulus -in /etc/ssl/certs/example_com_chained.crt | openssl md5
openssl rsa -noout -modulus -in /etc/ssl/certs/example_com.key | openssl md5

If both commands return the exact same hash (like (stdin)= a1b2c3d4e5f6…), your keypair matches. If they differ, the CRT was issued against a different CSR/private key than the one on disk.

Next, test the intermediate trust chain with OpenSSL:

openssl verify -untrusted /etc/ssl/certs/example_com.ca-bundle /etc/ssl/certs/example_com.crt

If the chain is built properly, OpenSSL prints example_com.crt: OK.

Configure Nginx to Serve the Namecheap SSL Bundle

With the bundle and key verified, open your Nginx server block (usually at /etc/nginx/sites-available/example.com on Debian/Ubuntu systems).

Add a port 80 block to force HTTPS, and update your port 443 block to point directly to example_com_chained.crt and example_com.key:

server { listen 80; listen [::]:80; server_name example.com www.example.com; # Enforce HTTPS redirect return 301 https://$host$request_uri;
}
server { listen 443 ssl http2; listen [::]:443 ssl http2; server_name example.com www.example.com; root /var/www/example.com/public; index index.html index.php; # Chained Certificate and Private Key ssl_certificate /etc/ssl/certs/example_com_chained.crt; ssl_certificate_key /etc/ssl/certs/example_com.key; # TLS Protocols and Ciphers ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384'; ssl_prefer_server_ciphers on; # Session Cache for Handshake Performance ssl_session_cache shared:SSL:10m; ssl_session_timeout 1d; ssl_session_tickets off; location / { try_files $uri $uri/ =404; }
}

If you’re proxying traffic to containerized backend apps, check our walkthrough on how to deploy Docker Compose apps with Namecheap DNS and SSL.

Always test your syntax before reloading the service:

sudo nginx -t

Once you get syntax is ok and test is successful, reload Nginx:

sudo systemctl reload nginx

Fix the Classic Gotchas and Handshake Errors

These are the three most common roadblocks you’ll hit with Namecheap certs on Nginx:

1. The “SSL_ERROR_RX_RECORD_TOO_LONG” Error

This error means a client sent an HTTPS request to a port where Nginx is listening for plain HTTP. Check your 443 server block and verify you have the ssl parameter on the listen directive:

# Broken:
listen 443; # Fixed:
listen 443 ssl;

2. Redirect Loops Behind Cloudflare or Reverse Proxies

If traffic flows through an edge proxy or CDN before reaching your server, mismatched SSL modes between the proxy and Nginx can trigger infinite redirect loops. If you run into that loop, see our guide on how to fix SSL ERR_TOO_MANY_REDIRECTS on Nginx behind a CDN.

3. SEC_ERROR_UNKNOWN_ISSUER on Firefox and Android

If Chrome on your laptop opens the site fine but Firefox or a phone screams about an untrusted issuer, you pointed ssl_certificate to example_com.crt instead of example_com_chained.crt. Desktop Chrome caches intermediate certs from other browsing sessions; Firefox and curl evaluate the chain strictly. Pointing Nginx to the combined bundle fixes this immediately.

Enable OCSP Stapling and Security Headers

OCSP stapling speeds up the initial TLS handshake. Instead of forcing every visitor’s browser to reach out to Sectigo to check revocation status, Nginx queries Sectigo periodically, caches the signed proof, and hands it straight to the browser during the handshake.

Drop these directives into your port 443 block:

# OCSP Stapling
ssl_stapling on;
ssl_stapling_verify on;
ssl_trusted_certificate /etc/ssl/certs/example_com_chained.crt;
resolver 1.1.1.1 8.8.8.8 valid=300s;
resolver_timeout 5s; # Security Headers
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
add_header X-Frame-Options DENY always;
add_header X-Content-Type-Options nosniff always;

For more details on fine-tuning TLS parameters, check the Nginx HTTP SSL Module documentation. Reload Nginx after saving.

Test Your SSL Configuration with OpenSSL and SSL Labs

Don’t trust just your daily browser to verify an SSL setup. Run a direct handshake test from your terminal with OpenSSL’s s_client:

openssl s_client -connect example.com:443 -servername example.com

Check the certificate chain section near the top of the output:

Certificate chain
0 s:CN = example.com
i:C = GB, ST = Greater Manchester, L = Salford, O = Sectigo Limited, CN = Sectigo RSA Domain Validation Secure Server CA
1 s:C = GB, ST = Greater Manchester, L = Salford, O = Sectigo Limited, CN = Sectigo RSA Domain Validation Secure Server CA
i:C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority
2 s:C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority
i:C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services

You should see level 0 (your domain), level 1 (intermediate CA), and level 2 (root CA). If it cuts off at 0, your CA-bundle wasn’t merged or loaded properly.

Finally, run your domain through the Qualys SSL Labs Server Test to confirm you have an A+ rating and no weak ciphers active.

Frequently Asked Questions

Do I need to include the root certificate in the CA-bundle for Nginx?

Nginx doesn’t strictly require the root cert because clients already store trusted root CAs locally. That said, keeping Namecheap’s full .ca-bundle appended—intermediates plus root anchor—is standard practice and keeps legacy mobile devices from choking on handshakes.

Can I use Certbot to automate Namecheap SSL renewals?

No, standard paid Namecheap SSLs (like PositiveSSL or EssentialSSL) cannot be renewed via Certbot because they require manual re-issuance and validation. If you want full renewal automation on your Namecheap domain, take a look at our guide on setting up Let’s Encrypt wildcard SSL with Certbot DNS-01 on Nginx.

What happens if I combine the CA-bundle before the CRT file?

If you run cat example_com.ca-bundle example_com.crt > bundle.crt, Nginx serves the intermediate cert first. When clients connect, Nginx presents the Sectigo intermediate as the server certificate. Browsers will immediately block the site with a Common Name mismatch error.

How long does Namecheap SSL validation take?

For standard domain-validated (DV) certs, it usually takes between 5 and 15 minutes after you configure the DNS CNAME or HTTP file verification record. Once it shows as active in Namecheap, grab the zip and chain the files on your server using the steps above.

all_in_one_marketing_tool