
Hosting a website on your own Centos 7 VPS gives you full control over configuration, performance, and security, something shared hosting simply cannot match. This guide walks through the complete process of pointing a domain to your Centos 7 VPS, configuring an Apache VirtualHost, and securing the site with a free, auto-renewing SSL certificate from Lets Encrypt. Whether you are hosting a single website or preparing your Centos 7 VPS to serve multiple domains, this 2026 updated walkthrough covers DNS setup, Apache installation, VirtualHost configuration, and SSL automation in one place.
One thing has changed significantly since this guide was first published: Centos 7 officially reached end of life on June 30, 2024. The distribution no longer receives security patches, and its default package mirrors have been taken offline. That does not mean a Centos 7 VPS cannot still be configured and used, but it does mean a few extra steps are now required before yum will work at all, and it means you should treat this guide as a path to a working test or legacy setup rather than a long-term production recommendation. Each of those changes is called out clearly in the relevant step below, along with the reasoning behind it.
By the end of this guide, your server will be running Apache with a properly configured VirtualHost, serving your domain over HTTPS with a certificate that renews itself automatically.
Prerequisites:
- A VPS running Centos 7
- A domain name (for example, yourdomain.com)
- SSH access to your server as a user with sudo privileges
A Note on Centos 7 End of Life Before You Begin
Centos 7 reached its official end of life on June 30, 2024. After that date, the CentOS project stopped publishing updates, security patches, and bug fixes for the distribution, and the default package mirrors referenced by mirrorlist.centos.org were taken offline. If you run yum update or yum install on a stock Centos 7 VPS image today without changing anything, you will most likely see a 404 error such as “Could not retrieve mirrorlist,” because the server is still trying to reach mirrors that no longer exist.
This does not mean the operating system stops working. Existing services continue running normally. What it means is that the package manager needs to be redirected to the CentOS Vault, an archive of the final released packages, before you can install anything new on your Centos 7 VPS. The Vault does not receive security updates either, since it is a frozen snapshot, so a Centos 7 VPS configured this way is suitable for learning, testing, and short-term or legacy workloads, but it should not be treated as a long-term production platform. For any new production deployment, CloudMinister recommends AlmaLinux 9, Rocky Linux 9, or Ubuntu LTS instead of Centos 7. If you are following this guide because you already operate an existing Centos 7 VPS, the steps below will get VirtualHost and SSL working correctly, and we will flag the Vault repository fix as a required first step rather than an optional one.
To point your repositories at the Vault, run the following on your Centos 7 VPS before anything else:
# Check your exact CentOS 7 point release first
cat /etc/centos-release
# Back up the existing repo files, then disable them
sudo mkdir -p /etc/yum.repos.d/old
sudo mv /etc/yum.repos.d/CentOS-Base.repo /etc/yum.repos.d/old/ 2>/dev/null
sudo mv /etc/yum.repos.d/CentOS-*.repo /etc/yum.repos.d/old/ 2>/dev/null
# Point yum at the CentOS Vault archive instead of the dead mirrors
sudo sed -e 's/mirror.centos.org/vault.centos.org/g' \
-e 's/^#.*baseurl=http/baseurl=http/g' \
-e 's/^mirrorlist=http/#mirrorlist=http/g' \
-i /etc/yum.repos.d/old/CentOS-Base.repo 2>/dev/null
# Clear the yum cache and rebuild it against the new source
sudo yum clean all
sudo yum makecache
If the sed based fix does not fully resolve the mirror errors on your specific Centos 7 VPS image, the more reliable option is to write a fresh repo file that points directly at the Vault path for your exact point release (for example 7.9.2009), as documented by CentOS Vault mirrors. Once yum makecache completes without 404 errors, you can proceed with the rest of this guide.
Step 1: Point Your Domain to the Server
Before touching your Centos 7 VPS terminal, you need to link your domain name to the server’s IP address through DNS.
- Log in to your domain registrar’s website (for example GoDaddy, Freenom, or Cloudflare).
- Open the DNS management section for your domain.
- Create or edit the A Records for your domain and the www subdomain so both point to your server’s public IP address:
| Record Type | Name / Host | Value / Answer |
| A | @ (or leave blank) | your_server_ip |
| A | www | your_server_ip |
DNS propagation can take anywhere from a few minutes to around 48 hours depending on your registrar, your previous DNS records, and the TTL value set on the record, though most changes today are visible within 15 to 60 minutes. This is a good step to complete early while you configure the rest of your Centos 7 VPS. You can check propagation status at any time using a public DNS checker or by running dig yourdomain.com from a separate machine.
Step 2: Server Setup and Apache Installation on Centos 7 VPS
Connect to your server via SSH and make sure Apache (httpd) is installed and running on your Centos 7 VPS. Assuming you have already redirected yum to the Vault as described above, the standard installation commands work exactly as they always have.
# Update the system packages (now pulling from the Vault archive)
sudo yum update -y
# Install the Apache web server (httpd)
sudo yum install -y httpd
# Start Apache and enable it to launch on boot
sudo systemctl start httpd
sudo systemctl enable httpd
# Check that Apache is active
sudo systemctl status httpd
# If firewalld is running, allow HTTP and HTTPS traffic
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --reload
Confirming that firewalld allows both HTTP and HTTPS traffic at this stage avoids a common issue where a fully configured VirtualHost still appears inaccessible from outside the Centos 7 VPS simply because the firewall is blocking the ports. If your VPS provider also enforces a separate cloud-level firewall or security group in front of the server, remember to open ports 80 and 443 there as well, since the host firewall and the provider firewall are two independent layers.
Step 3: Create the Website Directory and Content
It is good practice to store website files on your Centos 7 VPS in a clean, predictable directory structure, especially if you plan to host more than one domain on the same server later.
# Create a directory for your website files
# Use -p to create parent directories if they do not exist
sudo mkdir -p /var/www/yourdomain.com/public_html
# Create a simple index.html page for testing
sudo vi /var/www/yourdomain.com/public_html/index.html
Add the following content to the index.html file:
<html>
<head>
<title>Welcome to yourdomain.com!</title>
</head>
<body>
<h1>Success! The yourdomain.com VirtualHost is working on this Centos 7 VPS!</h1>
</body>
</html>
Apache on Centos 7 typically runs as the apache user and group by default. If you later upload files through SFTP as a different user, make sure the directory and file ownership either belongs to that user or is readable by the apache user, otherwise you may see a 403 Forbidden error even though the VirtualHost configuration itself on your Centos 7 VPS is correct.
Step 4: Configure the Apache VirtualHost on Centos 7 VPS
Create a new configuration file for your domain. Apache loads all .conf files from the /etc/httpd/conf.d/ directory, which makes managing multiple domains on a single Centos 7 VPS straightforward, since each domain simply gets its own file.
# Create a new configuration file for your domain
sudo vi /etc/httpd/conf.d/yourdomain.com.conf
Paste the following configuration, replacing all instances of yourdomain.com with your actual domain:
<VirtualHost *:80>
ServerName yourdomain.com
ServerAlias www.yourdomain.com
ServerAdmin [email protected]
DocumentRoot /var/www/yourdomain.com/public_html
<Directory "/var/www/yourdomain.com/public_html">
Options -Indexes +FollowSymLinks
AllowOverride All
Require all granted
</Directory>
ErrorLog /var/log/httpd/yourdomain.com-error.log
CustomLog /var/log/httpd/yourdomain.com-access.log combined
</VirtualHost>
The ServerName and ServerAlias directives tell Apache which requests this block should handle, which matters once more than one VirtualHost exists on the same Centos 7 VPS. The AllowOverride All directive enables .htaccess files inside the document root, which is required if you plan to install WordPress or another CMS that relies on .htaccess for permalinks and redirects.
Before restarting Apache on your Centos 7 VPS, validate the configuration file for syntax errors:
sudo apachectl configtest
# If it says Syntax OK, proceed. If not, check the file for typos.
# Restart Apache to apply the new VirtualHost configuration
sudo systemctl restart httpd
Test it: at this point, visiting http://your_server_ip should show the default Apache page. Once DNS has propagated, visiting http://yourdomain.com should display the page you created on your Centos 7 VPS.
Step 5: Secure Your Site with a Free SSL Certificate from Lets Encrypt
Certbot is used to automatically obtain and configure SSL on your Centos 7 VPS. Because Centos 7 ships with Python 2 as its system Python, the correct EPEL package for Apache integration is named python2-certbot-apache, and that naming is expected and correct, it is not a typo or a legacy leftover.
# Enable the EPEL repository, which contains the certbot package
sudo yum install -y epel-release
# Install certbot and the Apache plugin
sudo yum install -y certbot python2-certbot-apache
# Run certbot and follow the interactive prompts to secure your site
sudo certbot --apache
If yum install epel-release fails with a mirror or 404 error, it almost always means the Vault redirection from the earlier step has not fully taken effect on your Centos 7 VPS. Re-check your repo files in /etc/yum.repos.d/ and confirm every baseurl points at vault.centos.org rather than mirror.centos.org or mirrorlist.centos.org before trying again.
The tool will:
- Ask for an email address for urgent renewal notices.
- Ask you to agree to the Terms of Service.
- List the domains found in your Apache configuration so you can select the ones to secure.
- Ask if you want to redirect all HTTP traffic to HTTPS. Choosing the redirect option is recommended for the strongest security posture on a Centos 7 VPS.
Certbot will automatically edit your VirtualHost file to add the certificate paths and, if you chose the redirect option, add a second VirtualHost block on port 80 that forwards traffic to HTTPS. You can open the .conf file afterward to see exactly what changed.
To confirm that automatic renewal is working correctly:
sudo certbot renew --dry-run
If this command runs without errors, certificates on your Centos 7 VPS will renew automatically going forward, since Lets Encrypt certificates are valid for 90 days at a time. Certbot installs a systemd timer or a cron job during setup that checks twice daily and renews any certificate within 30 days of expiry, so no manual renewal is normally required once this step passes.
Step 6: Final Test
- Visit your domain in a browser at https://yourdomain.com. You should see your test page along with a secure padlock icon confirming the certificate is active.
- Test the HTTP to HTTPS redirect by visiting http://yourdomain.com. It should automatically forward to the secure https version.
- For a thorough SSL check on your Centos 7 VPS, use a tool such as SSL Labs SSL Test, which grades your certificate chain, protocol support, and cipher configuration.
Troubleshooting Common Issues on a Centos 7 VPS
A few issues come up repeatedly when configuring VirtualHost and SSL on a Centos 7 VPS. The most common ones are listed below along with their fixes.
- 403 Forbidden on the test page: usually a file permissions or SELinux issue. Confirm the document root and index.html are readable by the apache user, and check SELinux context with ls -Z if SELinux is enforcing on your Centos 7 VPS.
- Certbot cannot find a VirtualHost for the domain: this happens when ServerName in the VirtualHost block does not exactly match the domain you are requesting a certificate for. Correct the ServerName directive, run apachectl configtest, restart httpd, then re-run certbot.
- yum commands return 404 or mirror errors: this is the Centos 7 end of life issue described earlier. Redirect the repo files to vault.centos.org and clear the yum cache before continuing.
- Site loads over HTTP but not HTTPS: confirm port 443 is open both in firewalld on the Centos 7 VPS and in any external cloud firewall or security group, since these are separate layers.
- Certificate renewal test fails: run certbot certificates to see the exact stored configuration, and confirm the domain still correctly resolves to the same server IP, since Lets Encrypt re-validates domain ownership on every renewal.
Understanding VirtualHosts on a Centos 7 VPS
A VirtualHost is Apache’s mechanism for hosting more than one website on a single server using a single IP address. Without VirtualHosts, a Centos 7 VPS running Apache would only be able to serve one website per IP address, which would make multi-site hosting impractical and expensive. Each VirtualHost block tells Apache which domain name it should respond to, where the files for that domain live on disk, and where to write logs specific to that domain.
There are two common types of VirtualHost configuration: name-based and IP-based. Name-based VirtualHosts, which is what this guide uses, rely on the HTTP Host header sent by the browser to determine which site to serve, and multiple domains can share the same IP address and port. IP-based VirtualHosts instead bind each domain to a separate IP address, which is rarely necessary today and mostly used for very old SSL implementations that predated Server Name Indication. Every modern browser and every current SSL certificate on a Centos 7 VPS supports SNI, so name-based VirtualHosts with SSL work correctly for practically all visitors.
Apache processes VirtualHost files in the order they are loaded from /etc/httpd/conf.d/, and it matches an incoming request to the first ServerName or ServerAlias that matches the Host header. If no VirtualHost matches, Apache falls back to the first VirtualHost block defined, which is why it is good practice on a busy Centos 7 VPS to define an explicit default VirtualHost that either serves a placeholder page or redirects unmatched requests, rather than silently letting one of your real sites catch traffic intended for a domain that has not been configured yet.
Hardening Apache on a Centos 7 VPS After Setup
Once your VirtualHost and SSL certificate are working, a few additional configuration changes are worth making on a Centos 7 VPS before pointing real traffic at it. These are not strictly required for the site to function, but they meaningfully reduce the attack surface of the server.
- Disable directory listing everywhere: the Options -Indexes directive used in the VirtualHost block above already prevents Apache from listing files in a directory that has no index file, which stops visitors from browsing your file structure directly.
- Hide the Apache version banner: edit /etc/httpd/conf/httpd.conf and set ServerTokens Prod and ServerSignature Off, then restart httpd. This prevents error pages and response headers from revealing the exact Apache and OS version running on your Centos 7 VPS, which reduces the information available to automated vulnerability scanners.
- Restrict access to sensitive files: add a Directory or FilesMatch block that denies access to .htaccess, .git directories, and configuration files that should never be served over HTTP.
- Set a strong TLS configuration: certbot configures a reasonable default, but you can further restrict the SSLProtocol and SSLCipherSuite directives in the certbot-generated VirtualHost block to disable older TLS versions if your audience does not require them.
- Keep httpd and mod_ssl updated: even on a Centos 7 VPS running from Vault repositories, periodically check for updated httpd and mod_ssl packages, since these are the components most directly exposed to the internet.
Backing Up Your VirtualHost Configuration
Before making further changes to a working setup, it is worth backing up the VirtualHost configuration file and the SSL certificate paths on your Centos 7 VPS. Configuration files in /etc/httpd/conf.d/ are small text files and cost very little to back up regularly, but losing one means re-creating the VirtualHost block from scratch and re-running certbot.
# Back up the VirtualHost configuration
sudo cp /etc/httpd/conf.d/yourdomain.com.conf /root/backups/yourdomain.com.conf.bak
# Lets Encrypt certificates and keys live under /etc/letsencrypt
sudo tar -czf /root/backups/letsencrypt-backup.tar.gz /etc/letsencrypt
Store these backups somewhere other than the Centos 7 VPS itself, such as an offsite object storage bucket or a separate backup server, so that a full server failure does not also take out your only copy of the configuration.
Why This Setup Still Matters in 2026
Even with Centos 7 past its end of life, understanding how to manually configure Apache VirtualHosts and SSL certificates on a Centos 7 VPS remains a useful, transferable skill. The VirtualHost pattern, one configuration file per domain inside /etc/httpd/conf.d/, and the certbot workflow for Lets Encrypt certificates, are functionally identical on modern RHEL-family distributions such as AlmaLinux 9 and Rocky Linux 9, which use the same httpd package and the same certbot Apache plugin naming convention, aside from the Python 2 versus Python 3 package prefix.
If you are maintaining an existing Centos 7 VPS for legacy reasons, this guide gets you a working, encrypted site today. If you are starting a new project, use the same steps as a template on a currently supported distribution, and treat the Centos 7 specific Vault redirection step as something you will not need to repeat elsewhere.
Hosting Multiple Domains on One Centos 7 VPS
Once you are comfortable with the VirtualHost pattern described above, adding a second or third domain to the same Centos 7 VPS is largely a matter of repeating Steps 1 through 5 with a different domain name and a different document root. This is one of the main practical advantages of running your own VPS instead of shared hosting: a single server can serve many independent websites, each with its own configuration file, its own logs, and its own SSL certificate, as long as the underlying hardware has enough CPU, memory, and disk to handle the combined traffic.
A few practical points to keep in mind when scaling a Centos 7 VPS to multiple domains:
- Keep one .conf file per domain: resist the temptation to combine multiple VirtualHost blocks into a single file. Separate files make it much easier to disable, remove, or debug one site without touching the others.
- Watch resource usage as sites are added: run tools such as top, free -m, and df -h periodically on your Centos 7 VPS to confirm memory, CPU, and disk usage stay within safe limits as traffic grows across all hosted domains.
- Request certificates together where practical: certbot can secure multiple domains in a single command using the -d flag repeated for each domain, which is convenient when domains share a renewal schedule, though separate certificates per domain also work fine and are what this guide has demonstrated.
- Separate logs per domain: the ErrorLog and CustomLog directives in each VirtualHost block, as shown in Step 4, keep each domain’s log entries in their own file, which makes troubleshooting a specific site’s issues far quicker on a Centos 7 VPS hosting several domains at once.
Monitoring Apache and SSL Health on a Centos 7 VPS
A working VirtualHost and a valid SSL certificate on the day you set them up does not guarantee they stay that way. Ongoing monitoring on a Centos 7 VPS catches problems, such as a failed certificate renewal or an Apache crash, before visitors notice them.
- Check Apache status regularly: sudo systemctl status httpd shows whether the service is active, and journalctl -u httpd -n 50 shows recent log entries if something has gone wrong.
- Monitor certificate expiry independently: even though certbot renews automatically, an external uptime or SSL monitoring service that checks your domain from outside the Centos 7 VPS gives you an independent confirmation that renewal actually worked and did not silently fail.
- Review Apache error logs periodically: sudo tail -f /var/log/httpd/yourdomain.com-error.log while testing the site can surface permission issues, missing files, or misconfigured redirects immediately.
- Watch for repeated failed renewal attempts: certbot logs its renewal attempts to /var/log/letsencrypt/, and reviewing this log occasionally on your Centos 7 VPS confirms the renewal timer is actually running as expected rather than assuming it silently works forever.
Conclusion
You have successfully configured a Centos 7 VPS to host a website on a custom domain using Apache VirtualHosts, and secured it with a free, auto-renewing SSL certificate from Lets Encrypt. This guide covered the full path from DNS configuration through Apache installation, VirtualHost setup, and certificate automation, and also addressed the one issue that did not exist when this topic was first written about: a Centos 7 VPS today needs its package repositories redirected to the CentOS Vault before yum will function at all, since the distribution reached end of life on June 30, 2024. The same VirtualHost pattern can be repeated for every additional domain you add to the server, and this setup forms a solid foundation for hosting WordPress sites, custom web applications, or static sites on a Centos 7 VPS, provided the server has enough CPU, memory, and disk to handle the combined traffic.
If you are maintaining an existing Centos 7 VPS for legacy reasons or because a specific application still requires it, this guide gets you a working, encrypted site today using the Vault repository workaround described above. If you are starting a new project rather than maintaining an old one, use this same VirtualHost and SSL workflow as a template on a currently supported operating system such as AlmaLinux 9, Rocky Linux 9, or Ubuntu LTS instead, since an unsupported Centos 7 VPS will keep accumulating unpatched vulnerabilities for as long as it remains in service, no matter how correctly the VirtualHost and SSL configuration itself has been set up.

He is the CEO and Founder with over a decade of experience in cloud infrastructure, DevOps, and server optimization. With a strong vision and hands-on leadership approach, he has built scalable, secure, and high-performance cloud solutions trusted by businesses across industries.



