Emergency server help: get in touch

Install OpenLiteSpeed and WordPress on AlmaLinux 10 (No Panel)

Install OpenLiteSpeed, LSPHP 8.4, MariaDB and WordPress on AlmaLinux 10 from the official LiteSpeed repository, with HTTPS and LiteSpeed Cache.

Published 8 min read

Short answer: Add the LiteSpeed repository with wget -O - https://repo.litespeed.sh | bash, install openlitespeed and an LSPHP build such as lsphp84 with its MySQL, GD, XML and mbstring modules, install mariadb-server from AlmaLinux AppStream, then create a virtual host in the WebAdmin console on port 7080 that points at your WordPress folder and uses LSPHP. Enable .htaccess rewrites, add a Let’s Encrypt certificate with certbot, and install the LiteSpeed Cache plugin.

Commands checked against the official OpenLiteSpeed documentation (linked below) on 6 October 2026; not yet run on our lab servers. Package names were checked against the LiteSpeed and AlmaLinux 10 repository metadata on the same day.

Before you start

  • A fresh AlmaLinux 10 server with root access. AlmaLinux 10 needs a CPU with x86-64-v3; check with /lib64/ld-linux-x86-64.so.2 --help | grep x86-64-v3.
  • A domain (example.com below) with A records for example.com and www.example.com pointing to the server.
  • Nothing else listening on ports 80, 443 or 7080. Do not install Apache or nginx alongside.

Update the system first:

dnf -y update && reboot

Add the LiteSpeed repository

The OpenLiteSpeed docs use LiteSpeed’s repository script. It detects the OS and writes /etc/yum.repos.d/litespeed.repo with the EL10 package path. Read it before you pipe it to a shell; on EL9 and newer it also installs the Remi release package and epel-release, and enables the CRB repository, so you end up with three extra repositories.

curl -s https://repo.litespeed.sh -o /root/litespeed-repo.sh
less /root/litespeed-repo.sh        # review it
bash /root/litespeed-repo.sh
dnf repolist

Install OpenLiteSpeed and LSPHP

dnf -y install openlitespeed

When we read the repository metadata on 6 October 2026, the EL10 openlitespeed package (1.9.3) pulled in lsphp83 and a few of its modules as dependencies. For a new WordPress site, install a current LSPHP build with the modules WordPress uses. These package names all exist in the EL10 repository:

dnf -y install lsphp84 lsphp84-common lsphp84-mysqlnd lsphp84-gd lsphp84-mbstring \
  lsphp84-xml lsphp84-process lsphp84-opcache lsphp84-intl lsphp84-zip lsphp84-pecl-imagick

/usr/local/lsws/lsphp84/bin/php -v
/usr/local/lsws/lsphp84/bin/php -m | grep -Ei "mysqli|gd|mbstring|xml|zip|intl|imagick"

Use dnf search lsphp to see other versions. On RHEL-family systems the MySQL module is called -mysqlnd; on Debian and Ubuntu it is -mysql.

Start the server and set the WebAdmin password:

systemctl enable --now lsws
/usr/local/lsws/admin/misc/admpass.sh

Open the firewall for the web ports, and allow the admin console only from your own address (198.51.100.25 here):

firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.25" port port="7080" protocol="tcp" accept'
firewall-cmd --reload

The console is now at https://203.0.113.10:7080/ with a self-signed certificate. The default virtual host is called Example and listens on port 8088; you can leave it or delete it later.

Install MariaDB and create the database

AlmaLinux 10 AppStream ships MariaDB 10.11 as mariadb-server (10.11.18 when we checked).

dnf -y install mariadb-server
systemctl enable --now mariadb
mariadb-secure-installation

Create a database and user for WordPress. Use your own strong password:

mariadb <<'SQL'
CREATE DATABASE wp_example CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'wp_example'@'localhost' IDENTIFIED BY 'change-this-password';
GRANT ALL PRIVILEGES ON wp_example.* TO 'wp_example'@'localhost';
FLUSH PRIVILEGES;
SQL

Download WordPress and create the virtual host

The OpenLiteSpeed docs keep each virtual host in its own folder with conf, html and logs subfolders. Follow the same layout:

mkdir -p /usr/local/lsws/example.com/{conf,html,logs}
cd /tmp && curl -sO https://wordpress.org/latest.tar.gz
tar xzf latest.tar.gz -C /usr/local/lsws/example.com/html --strip-components=1
grep -E "^(user|group)" /usr/local/lsws/conf/httpd_config.conf

The last command shows the user and group OpenLiteSpeed runs PHP as. Give that account ownership of the site so WordPress can write uploads and updates (replace nobody:nobody with what the command printed):

chown -R nobody:nobody /usr/local/lsws/example.com/html

Now configure the site in the WebAdmin console:

  1. Server Configuration > External App > Add: type LSAPI, name lsphp84, address uds://tmp/lshttpd/lsphp84.sock, command /usr/local/lsws/lsphp84/bin/lsphp. Keep Max Connections and the PHP_LSAPI_CHILDREN environment value equal (the docs use 10 for both).
  2. Virtual Hosts > Add: Virtual Host Name example.com, Virtual Host Root $SERVER_ROOT/example.com, Config File $SERVER_ROOT/conf/vhosts/example.com/vhost.conf (the console offers to create it).
  3. In that virtual host, General tab: Document Root $VH_ROOT/html/, Domain Name example.com, Index Files index.php, index.html.
  4. Script Handler tab: add suffix php, handler type LiteSpeed SAPI, handler lsphp84.
  5. Rewrite tab: set Enable Rewrite and Auto Load from .htaccess to Yes.
  6. Listeners > Add: name HTTP, IP Address ANY IPv4, port 80. Under Virtual Host Mappings map example.com to the domains example.com, www.example.com.
  7. Click Graceful Restart.

Browse to http://example.com/ and run the WordPress installer with the database details from the previous step.

Add HTTPS with Let’s Encrypt

EPEL 10 has certbot (4.2.0 when we checked). Use the webroot method so certbot never stops the web server, and restart OpenLiteSpeed after each renewal so it loads the new certificate:

dnf -y install certbot
certbot certonly --webroot -w /usr/local/lsws/example.com/html \
  -d example.com -d www.example.com \
  --deploy-hook "systemctl restart lsws"

Then add an HTTPS listener in WebAdmin: Listeners > Add, name HTTPS, IP ANY, port 443, Secure Yes. On its SSL tab set Private Key File to /etc/letsencrypt/live/example.com/privkey.pem, Certificate File to /etc/letsencrypt/live/example.com/fullchain.pem and Chained Certificate to Yes. Map the same virtual host on this listener and restart. Finally, set the WordPress and site URLs to https:// under Settings > General.

OpenLiteSpeed also has a built-in ACME feature that issues certificates for you. Use one method, not both.

  1. In WordPress, install and activate the LiteSpeed Cache plugin.
  2. Under Settings > Permalinks choose Post name and save. WordPress writes its rules to .htaccess.
  3. Restart OpenLiteSpeed so it loads the new .htaccess: systemctl restart lsws. This restart is needed every time rewrite rules in .htaccess change.

EPEL 10 also packages wp-cli (2.12.0 when we checked) if you prefer to manage plugins and updates from the shell: dnf -y install wp-cli.

Check that it worked

systemctl status lsws --no-pager
curl -sI https://example.com/ | head -5
curl -s -o /dev/null -w "%{http_code}\n" https://example.com/sample-page/
/usr/local/lsws/lsphp84/bin/php -v
  • The site loads over HTTPS without warnings and a pretty permalink returns 200.
  • In WordPress, Tools > Site Health shows no missing required PHP modules.
  • Port 7080 is not reachable from other addresses.
  • A dry-run renewal works: certbot renew --dry-run.

Common problems

  • Permalinks return 404: rewrite is off, Auto Load from .htaccess is off, or OpenLiteSpeed was not restarted after WordPress wrote .htaccess.
  • Browser downloads PHP files: the virtual host has no script handler for php, or the external app name does not match.
  • 503 errors: check /usr/local/lsws/logs/error.log and /usr/local/lsws/logs/stderr.log. A wrong LSPHP path or a missing module is the usual cause.
  • WordPress asks for FTP details on updates: the site files are not owned by the user OpenLiteSpeed runs PHP as.
  • Error establishing a database connection: check the credentials in wp-config.php and that MariaDB is running.
  • Access denied in the audit log: AlmaLinux runs SELinux in enforcing mode; check ausearch -m avc -ts recent before you change any policy.

Official documentation: OpenLiteSpeed: Install from repository · OpenLiteSpeed: Configuration · OpenLiteSpeed: PHP · OpenLiteSpeed: SSL

Related: LiteSpeed Cache WordPress cPanel: Recommended Settings · Harden SSH AlmaLinux 9: Secure Setup in 15 Minutes · InnoDB Tuning MariaDB 11/12: Shared Hosting Settings · SSL Certificate Checker · Security Headers Checker

See also: LiteSpeed vs OpenLiteSpeed for Hosting Servers: Which to Pick · Stuck lsphp Processes on cPanel LiteSpeed: Diagnose and Kill Safely · PHP-FPM Calculator: pm.max_children and Spare Servers

Frequently asked questions

Does OpenLiteSpeed support AlmaLinux 10?

Yes. The OpenLiteSpeed docs list CentOS 8, 9 and 10 including RHEL derivatives such as AlmaLinux, and the LiteSpeed repository has EL10 packages.

Which PHP version should I use with WordPress on OpenLiteSpeed?

Use a supported LSPHP build such as lsphp84. The EL10 repository also has lsphp83 and lsphp85.

Do I need to restart OpenLiteSpeed after changing .htaccess?

Yes. OpenLiteSpeed reads rewrite rules from .htaccess only after a restart, unlike LiteSpeed Enterprise.

Where is the OpenLiteSpeed admin panel?

The WebAdmin console listens on port 7080. Set its password with /usr/local/lsws/admin/misc/admpass.sh and restrict the port in the firewall.

Can I use the stock AlmaLinux PHP packages instead of LSPHP?

The OpenLiteSpeed docs configure PHP through LSAPI external apps that point at LSPHP binaries. Use LSPHP from the LiteSpeed repository.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.