# How to Set Up SSL for Snipe-IT: Docker, Apache, and Nginx Configuration

> Secure your Snipe-IT deployment by setting up SSL. Learn to configure Docker, Apache, and Nginx for HTTPS, ensuring encrypted asset management and secure user access.

- Repository: [Grokability, Inc./snipe-it](https://github.com/grokability/snipe-it)
- Tags: how-to-guide
- Published: 2026-07-31

---

**To set up SSL for Snipe-IT, configure your web server to terminate HTTPS connections on port 443 using an X.509 certificate, then force HTTPS scheme in [`app/Providers/AppServiceProvider.php`](https://github.com/grokability/snipe-it/blob/main/app/Providers/AppServiceProvider.php) and set `APP_URL=https://your-domain` in the `.env` file to ensure Laravel generates secure URLs.**

Snipe-IT is a Laravel 12 application that requires two layers of SSL configuration: web-server termination for encrypted traffic and framework awareness to generate correct HTTPS URLs. The `grokability/snipe-it` repository provides Apache virtual-host templates and Docker startup scripts that automate SSL detection and configuration.

## Understanding SSL Architecture for Snipe-IT

Setting up SSL consists of two distinct parts. **Web-server termination** configures Apache, Nginx, or the Docker container to present an X.509 certificate and listen on port 443. **Laravel awareness** tells the framework that requests are secure so generated URLs, redirects, and the asset pipeline use `https://` instead of `http://`.

## Method 1: Docker SSL Setup (Recommended)

The official Docker image ships with an Apache virtual-host template at [`docker/001-default-ssl.conf`](https://github.com/grokability/snipe-it/blob/main/docker/001-default-ssl.conf) and a startup script at [`docker/startup.sh`](https://github.com/grokability/snipe-it/blob/main/docker/startup.sh) that automatically enables SSL when certificates are present.

### Generate SSL Certificates

Create the certificate directory and generate self-signed certificates for testing, or place CA-signed certificates in the same location:

```bash
mkdir -p /var/lib/snipeit/ssl
openssl req -newkey rsa:2048 -nodes -keyout /var/lib/snipeit/ssl/snipeit-ssl.key \
  -x509 -days 365 -out /var/lib/snipeit/ssl/snipeit-ssl.crt \
  -subj "/C=US/ST=State/L=City/O=Organization/CN=snipe.example.com"

```

### Enable SSL in the Container

The [`docker/startup.sh`](https://github.com/grokability/snipe-it/blob/main/docker/startup.sh) script checks for the presence of `snipeit-ssl.crt` and `snipeit-ssl.key` in `/var/lib/snipeit/ssl/` before running `a2enmod ssl` and `a2ensite default-ssl.conf`. According to the source code in [`docker/startup.sh`](https://github.com/grokability/snipe-it/blob/main/docker/startup.sh), this automation only triggers if both files exist at container startup.

After placing the certificates, rebuild and restart the containers:

```bash
docker compose up -d --build

```

## Method 2: Manual Apache SSL Installation

For traditional Apache installations without Docker, use the SSL configuration template from [`docker/001-default-ssl.conf`](https://github.com/grokability/snipe-it/blob/main/docker/001-default-ssl.conf) as your reference.

### Install Certificates

Place your certificate files in the expected directory:

```bash
sudo mkdir -p /var/lib/snipeit/ssl
sudo cp your-domain.crt /var/lib/snipeit/ssl/snipeit-ssl.crt
sudo cp your-domain.key /var/lib/snipeit/ssl/snipeit-ssl.key
sudo chown -R www-data:www-data /var/lib/snipeit/ssl

```

### Configure the SSL Virtual Host

Create [`/etc/apache2/sites-available/snipeit-ssl.conf`](https://github.com/grokability/snipe-it/blob/main//etc/apache2/sites-available/snipeit-ssl.conf) using the structure from [`docker/001-default-ssl.conf`](https://github.com/grokability/snipe-it/blob/main/docker/001-default-ssl.conf):

```apache
<IfModule mod_ssl.c>
    <VirtualHost *:443>
        ServerName snipe.example.com
        SSLEngine on
        SSLCertificateFile /var/lib/snipeit/ssl/snipeit-ssl.crt
        SSLCertificateKeyFile /var/lib/snipeit/ssl/snipeit-ssl.key
        DocumentRoot /var/www/html/public
        
        <Directory /var/www/html/public>
            AllowOverride All
            Require all granted
        </Directory>
    </VirtualHost>
</IfModule>

```

Enable the site and required modules:

```bash
sudo a2enmod ssl
sudo a2ensite snipeit-ssl.conf
sudo systemctl reload apache2

```

### Redirect HTTP to HTTPS

Add the following rewrite rules to your non-SSL virtual host to force secure connections:

```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

```

## Method 3: Nginx SSL Configuration

While the repository does not ship an Nginx configuration, apply the same certificate paths and Laravel HTTPS enforcement principles:

```nginx
server {
    listen 80;
    server_name snipe.example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    server_name snipe.example.com;

    ssl_certificate /var/lib/snipeit/ssl/snipeit-ssl.crt;
    ssl_certificate_key /var/lib/snipeit/ssl/snipeit-ssl.key;

    root /var/www/html/public;
    index index.php;

    location / {
        try_files $uri $uri/ /index.php?$query_string;
    }

    location ~ \.php$ {
        fastcgi_pass php-fpm:9000;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        include fastcgi_params;
    }
}

```

## Configuring Laravel for HTTPS

Regardless of your web server, you must inform Laravel that the application is running behind HTTPS. Edit [`app/Providers/AppServiceProvider.php`](https://github.com/grokability/snipe-it/blob/main/app/Providers/AppServiceProvider.php) to force the HTTPS scheme:

```php
use Illuminate\Support\Facades\URL;

public function boot()
{
    if (config('app.env') === 'production') {
        URL::forceScheme('https');
    }
}

```

Update the `.env` file to reflect the secure base URL:

```env
APP_URL=https://snipe.example.com

```

Clear the configuration cache to apply changes:

```bash
php artisan config:clear

```

The [`config/app.php`](https://github.com/grokability/snipe-it/blob/main/config/app.php) file uses this environment variable as the canonical base URL for redirects, password resets, and email notifications.

## Troubleshooting Common SSL Issues

- **Docker container does not listen on port 443**: Verify that `snipeit-ssl.crt` and `snipeit-ssl.key` exist in `/var/lib/snipeit/ssl/` before the container starts. The [`docker/startup.sh`](https://github.com/grokability/snipe-it/blob/main/docker/startup.sh) script only enables the SSL site if both files are present.
- **Laravel generates HTTP URLs**: Ensure `APP_URL` starts with `https://` and that `URL::forceScheme('https')` is present in [`app/Providers/AppServiceProvider.php`](https://github.com/grokability/snipe-it/blob/main/app/Providers/AppServiceProvider.php). Run `php artisan config:clear` after any `.env` changes.
- **Apache fails to start**: Check that certificate files exist at the paths specified in your virtual host and that the `www-data` user has read permissions.
- **Browser shows certificate warnings**: Self-signed certificates trigger security warnings. For production, use certificates from a recognized Certificate Authority or install your self-signed CA into client trust stores.

## Summary

- Place SSL certificates in `/var/lib/snipeit/ssl/snipeit-ssl.crt` and `/var/lib/snipeit/ssl/snipeit-ssl.key` for both Docker and manual Apache installations.
- The [`docker/startup.sh`](https://github.com/grokability/snipe-it/blob/main/docker/startup.sh) script auto-enables SSL when certificate files are present at container startup.
- Reference [`docker/001-default-ssl.conf`](https://github.com/grokability/snipe-it/blob/main/docker/001-default-ssl.conf) for the official Apache SSL virtual-host configuration.
- Force HTTPS scheme in [`app/Providers/AppServiceProvider.php`](https://github.com/grokability/snipe-it/blob/main/app/Providers/AppServiceProvider.php) using `URL::forceScheme('https')` to ensure Laravel generates secure URLs.
- Update `APP_URL` in `.env` to use `https://` and clear the config cache with `php artisan config:clear`.

## Frequently Asked Questions

### Why does Snipe-IT still generate HTTP links after enabling SSL?

Laravel generates URLs based on the `APP_URL` environment variable and the request scheme. If `APP_URL` still starts with `http://` or if `URL::forceScheme('https')` is missing from [`app/Providers/AppServiceProvider.php`](https://github.com/grokability/snipe-it/blob/main/app/Providers/AppServiceProvider.php), the framework will continue producing insecure URLs. Update both settings and clear the configuration cache.

### Can I use Let's Encrypt certificates with Snipe-IT Docker?

Yes. Mount your Let's Encrypt certificates to `/var/lib/snipeit/ssl/snipeit-ssl.crt` and `/var/lib/snipeit/ssl/snipeit-ssl.key` in the container volume. The [`docker/startup.sh`](https://github.com/grokability/snipe-it/blob/main/docker/startup.sh) script will detect these files and automatically enable the SSL virtual host defined in [`docker/001-default-ssl.conf`](https://github.com/grokability/snipe-it/blob/main/docker/001-default-ssl.conf).

### What file permissions are required for SSL certificates?

The web server process must read the certificate files. For Apache in Docker or traditional installs, ensure the `www-data` user can read `/var/lib/snipeit/ssl/snipeit-ssl.crt` and `/var/lib/snipeit/ssl/snipeit-ssl.key`. Set permissions with `chmod 644` for the certificate and `chmod 600` for the private key.

### Where is the SSL configuration stored in the Snipe-IT repository?

The Apache SSL template is located at [`docker/001-default-ssl.conf`](https://github.com/grokability/snipe-it/blob/main/docker/001-default-ssl.conf), and the startup logic that conditionally enables SSL is in [`docker/startup.sh`](https://github.com/grokability/snipe-it/blob/main/docker/startup.sh). The framework HTTPS enforcement belongs in [`app/Providers/AppServiceProvider.php`](https://github.com/grokability/snipe-it/blob/main/app/Providers/AppServiceProvider.php), while the base URL configuration is controlled by `APP_URL` in `.env` and [`config/app.php`](https://github.com/grokability/snipe-it/blob/main/config/app.php).