
OpenLiteSpeed is a free, open-source, high-performance web server that supports multiple connection protocols, including HTTP/2 and HTTP/3, with native PHP support for securely delivering dynamic web applications. It also features an intuitive graphical web administration console, enabling you to easily manage and create multiple virtual hosts on your server.
In this article, you are to install the OpenLiteSpeed web server on Ubuntu 22.04 and configure the web administration console to securely host web applications on your server.
Before you begin:
Have an Ubuntu 22.04 server.
Create a domain name A record pointing to the server IP address.
Access the server using SSH as a non-root user with sudo privileges.
OpenLiteSpeed is not available in the default APT repositories for Ubuntu 22.04. However, you can install it by using the latest repository setup script. Follow the steps below to download the script and execute it, allowing you to install the web server via the APT package manager
Download the latest OpenLiteSpeed repository setup script.
Run the script to add the OpenLiteSpeed repository information to your APT sources.
Output:
Install OpenLiteSpeed.
View the installed OpenLiteSpeed version on your server.
Your output should be similar to the one below.
OpenLiteSpeed uses the lshttpd.service system service, with the lsws alias, to manage web server processes through systemd. Follow the steps below to enable the OpenLiteSpeed service to start automatically at boot time and to manually start the web server.
Enable the service to automatically start at boot time.
Start the OpenLiteSpeed service.
View the OpenLiteSpeed service status and verify that it's running.
Output:
Stop the OpenLiteSpeed service.
Restart the service.
The OpenLiteSpeed web administration console runs on port 7080, with the default admin password located in /usr/local/lsws/admin/password. Follow the steps below to enable console access, update admin credentials, and configure OpenLiteSpeed to serve applications on HTTP port 80."
Run the OpenLiteSpeed admin script to create a custom username and password.
Enter a new administrator username in the User name prompt and press Enter to save the user.
Enter a strong password to use with your new administrative user.
Enter the user password again and press Enter to save your new administrative user details.
Allow connections to the OpenLiteSpeed admin port 7080 through the UFW firewall.
Reload the UFW rules to apply changes.
Access the OpenLiteSpeed port 7080 using your server IP in a web browser such as Chrome.
Accept the insecure SSL certificate warning and enter the administrative user details you created earlier.
<username you set earlier><password you set earlier>
Click Listeners on the main navigation bar to modify the default listening port on your webserver.
Click the view icon in the Actions section of the Default listener profile.
Click Edit in the top right of the Address Settings section to modify the listener details.
Change the Port field from 8088 to 80 to run all default virtual hosts on HTTP port 80.
Click the Save icon in the top right of the Address Settings section to save the new default listener settings.
Verify that a Configurations modified prompt displays. Then, find the LSWS PID option in the top right corner and click the Graceful Restart icon to apply your configuration changes.
Click Go when prompted to restart the OpenLiteSpeed webserver to apply changes.
OpenLiteSpeed lets you create virtual hosts with custom web root directories via the web administration console. Follow the steps below to create a new virtual host that serves web application files for the domain app.example.com and a custom web root directory on your server.
Create a new web root directory to use with your virtual host. For example, /usr/local/lsws/app.example.com.
Create the html, logs, and conf directories required by the OpenLiteSpeed webserver.
The above command creates the following sub-directories in your web root directory:
html: Contains the web application files served through OpenLiteSpeed using the virtual host domain.logs: Stores the virtual host access and error logs.conf: Stores site-specific configurations for use with the OpenLiteSpeed web server.Grant the OpenLiteSpeed console user and group lsadm full privileges to the web root directory.
Access your OpenLiteSpeed web administration console.
Click Virtual Hosts on the main navigation menu to set up a new virtual host.
Click the + Add option in the top right corner of the Virtual Host List section.
Enter the following virtual host configuration details in the respective fields. Replace app.example.com with your actual domain.
app.example.com$SERVER_ROOT/app.example.com/$SERVER_ROOT/conf/vhosts/$VH_NAME/vhconf.confYesYesYesServer UIDKeep the other virtual host values unchanged and click Save in the top right corner of the Virtual Host section to save changes.
Find and click the CLICK TO CREATE option when you receive a Please resolve the error(s) prompt to create a new vhconf.conf virtual host configuration in your web root directory.
Click Save to create the new virtual host configuration.
Verify that your new virtual host appears in the Virtual Hosts summary. Then, click View within the Actions section to modify the virtual host information.
Navigate to the General tab and click Edit to modify the virtual host with the following information.
$VH_ROOT/html/app.example.comYesYes
Click Save to apply the new virtual host configuration.
Navigate to the Log tab and click Edit within the Virtual Host Log section. Then, enter the following values in the respective fields to set up the error log details.
Yes$VH_ROOT/logs/error.logERROR10M30
Click Save to apply the new virtual host error log details.
Click Add within the Access Log section to set up the virtual host access log details. Then, enter the following values in the respective fields.
Own Log File$VH_ROOT/logs/access.log10M30
Click Save to apply the new virtual host access log details.
Navigate to the Rewrite tab and click edit within the Rewrite Control section to set up the virtual host rewrite configurations.
Enable Rewrite: Yes
Auto Load from .htaccess: Yes
Click Save to apply your virtual host rewrite configurations.
Navigate to Listeners on the main navigation bar.
Edit the Default Listener and click Add within the Virtual Host Mappings section to set up your virtual host listening details.
Click the Virtual Host drop-down and select your virtual host profile.
Enter your domain app.example.com in the Domains field to bind with the virtual host and serve web application files.
Click Save to update the virtual host mapping details, then click the Graceful Restart icon next to LSWS PID in the top right console section to restart OpenLiteSpeed.
When prompted, click Go to restart LiteSpeed and apply your web server settings.
Open your server's SSH session.
Create a new HTML application file index.html in your web root html directory.
Add the following contents to the file.
Save and close the file.
The above HTML application displays a Greetings from Vultr message when accessed in your web browser.
Allow connections to the default HTTP port 80 through the firewall to test your virtual host configurations.
Access your virtual host domain in a new web browser window and verify that OpenLiteSpeed delivers your web application files.
OpenLiteSpeed serves all virtual hosts on HTTP port 80, which supports unencrypted connections between the client and web server. To enable encrypted connections, HTTPS uses port 443 with SSL certificates to secure the communication between a web browser and the server. Follow the steps below to generate trusted Let's Encrypt SSL certificates and secure your OpenLiteSpeed web server.
Install the Certbot Let's Encrypt client tool using Snap.
Generate a new SSL Let's Encrypt SSL certificate using an HTTP-01 challenge and your virtual host web root directory. Replace app.example.com and admin@example.com with your actual details.
The command above generates a new Let's Encrypt SSL certificate for your virtual host domain app.example.com and its corresponding web root directory /usr/local/lsws/app.example.com/html/. Since Certbot doesn't support the OpenLiteSpeed web server profile, you will need to manually enable the generated certificate files in your virtual host configuration.
Test the Certbot SSL certificate renewal process.
Access your OpenLiteSpeed web administration dashboard.
Navigate to Listeners on the main navigation bar.
Click Add within the Listener List section to add a new listener.
Enter the following values in the respective field to listen for HTTPS requests on the server.
HTTPSANY IPv4443Yes
Click Save to add the new listener on your webserver.
Find the new HTTPS listener on your Listener list. Then, click View in the actions section to modify the listener details.
Click Add within the Virtual Host Mappings section to bind the listener to an existing virtual host on your server.
Enter the following details in the respective fields to bind your virtual host.
app.example.comapp.example.com
Click Save to apply the new virtual host mappings on your webserver.
Navigate to the SSL tab and click edit within the SSL Private Key & Certificate section to modify your certificate details.
Enter the following details in the respective fields to match your Let's Encrypt SSL certificate paths.
/etc/letsencrypt/live/app.example.com/privkey.pem/etc/letsencrypt/live/app.example.com/fullchain.pemYes
Click Save to apply the new SSL certificate details in your virtual host configuration.
Find the LSWS PID option and click Graceful Restart to restart the webserver.
Click GO when prompted to restart LiteSpeed and apply your configuration changes.
When running multiple virtual hosts on your server. Navigate to the Virtual Hosts tab, open your target virtual host, and click SSL to enable an SSL certificate to bind with the virtual host configuration.
UFW is enabled by default on Vultr Ubuntu servers. Configure it to allow connections to ports 7080, 443, and 80 as described below.
Enable UFW and allow connections to the SSH port 22 if it's inactive on your server.
Allow connections to the OpenLiteSpeed console port 7080.
Allow HTTP connections on the server.
Allow HTTPS connections.
Restart UFW to apply your firewall changes.
View the firewall status and verify that the new rules are active on your server.
Access your virtual host's domain using HTTPS in a new web browser window to test your SSL configurations.
In this article, you installed the OpenLiteSpeed webserver on Ubuntu 22.04 and set up a sample virtual host to securely deliver web applications on your server. The OpenLiteSpeed webserver application includes native support for PHP which allows you to run dynamic web applications depending on your development needs.
0 Comments
Be the first to comment and share your perspective with the community.