# Installing your mail certificate for ISPConfig

Category: [Certificates](https://www.cloudvip.com/en/faq/certificates.md)
Source page: [https://www.cloudvip.com/en/faq/certificates/installing-mail-certificate-for-ispconfig](https://www.cloudvip.com/en/faq/certificates/installing-mail-certificate-for-ispconfig)

You have followed the “Create a certificate signing request” procedure and received your SSL certificate signed by the trusted authority. Follow this procedure to install it:

Step 1 - copy the files received

You will receive a zip file from our support team containing:

votredomaine._be.ca-bundle -> the certification authority's intermediate certificates
votredomaine._be.crt -> your certificate

Copy these two files to the server.

Step 2 - copy your key to the correct location

Copy the key (ma-cle-privee.key) to the Postfix directory:

> cp ma-cle-privee.key /etc/postfix/smtpd.key 

Step 3 - copy your certificate to the correct location

> cat votredomaine._be.crt votredomaine._be.ca-bundle > /etc/postfix/smtpd.cert 

Step 3 - restart the services

> /etc/init.d/postfix restart
> /etc/init.d/dovecot restart
 
Step 4 - checks

Now check Dovecot over IMAP/S and POP3/S:

> openssl s_client -connect mail.votredomaine.be:pop3s
> openssl s_client -connect mail.votredomaine.be:imaps

Then check Postfix and its SMTP (25), SMTP/S (465) and SUBMISSION (587) ports:

> openssl s_client -connect mail.votredomaine.be:465
> openssl s_client -connect mail.votredomaine.be:smtp -starttls smtp
> openssl s_client -connect mail.votredomaine.be:submission -starttls smtp

If the certification authority's name appears and there are no errors, your certificate is working.

You can also check the dates using the following commands:

First, test the “SSL” ports:

> echo | openssl s_client -connect mail.votredomaine.be:pop3s 2>/dev/null | openssl x509 -noout -dates
> echo | openssl s_client -connect mail.votredomaine.be:imaps 2>/dev/null | openssl x509 -noout -dates
> echo | openssl s_client -connect mail.votredomaine.be:submissions 2>/dev/null | openssl x509 -noout -dates

Then test the “START TLS” ports:

> echo | openssl s_client -connect mail.votredomaine.be:smtp -starttls smtp 2>/dev/null | openssl x509 -noout -dates
> echo | openssl s_client -connect mail.votredomaine.be:submission -starttls smtp 2>/dev/null | openssl x509 -noout -dates
> echo | openssl s_client -connect mail.votredomaine.be:pop3 -starttls pop3 2>/dev/null | openssl x509 -noout -dates
> echo | openssl s_client -connect mail.votredomaine.be:imap -starttls imap 2>/dev/null | openssl x509 -noout -dates
