Short answer: Add the LiteSpeed repository with wget -O - https://repo.litespeed.sh | bash, install openlitespeed and an LSPHP build such as lsphp84 with its MySQL, GD, XML and mbstring modules, install mariadb-server from AlmaLinux AppStream, then create a virtual host in the WebAdmin console on port 7080 that points at your WordPress folder and uses LSPHP. Enable .htaccess rewrites, add a Let’s Encrypt certificate with certbot, and install the LiteSpeed Cache plugin.
Commands checked against the official OpenLiteSpeed documentation (linked below) on 6 October 2026; not yet run on our lab servers. Package names were checked against the LiteSpeed and AlmaLinux 10 repository metadata on the same day.
Table of Contents
Before you start
- A fresh AlmaLinux 10 server with root access. AlmaLinux 10 needs a CPU with x86-64-v3; check with
/lib64/ld-linux-x86-64.so.2 --help | grep x86-64-v3. - A domain (example.com below) with A records for
example.comandwww.example.compointing to the server. - Nothing else listening on ports 80, 443 or 7080. Do not install Apache or nginx alongside.
Update the system first:
dnf -y update && reboot
Add the LiteSpeed repository
The OpenLiteSpeed docs use LiteSpeed’s repository script. It detects the OS and writes /etc/yum.repos.d/litespeed.repo with the EL10 package path. Read it before you pipe it to a shell; on EL9 and newer it also installs the Remi release package and epel-release, and enables the CRB repository, so you end up with three extra repositories.
curl -s https://repo.litespeed.sh -o /root/litespeed-repo.sh
less /root/litespeed-repo.sh # review it
bash /root/litespeed-repo.sh
dnf repolist
Install OpenLiteSpeed and LSPHP
dnf -y install openlitespeed
When we read the repository metadata on 6 October 2026, the EL10 openlitespeed package (1.9.3) pulled in lsphp83 and a few of its modules as dependencies. For a new WordPress site, install a current LSPHP build with the modules WordPress uses. These package names all exist in the EL10 repository:
dnf -y install lsphp84 lsphp84-common lsphp84-mysqlnd lsphp84-gd lsphp84-mbstring \
lsphp84-xml lsphp84-process lsphp84-opcache lsphp84-intl lsphp84-zip lsphp84-pecl-imagick
/usr/local/lsws/lsphp84/bin/php -v
/usr/local/lsws/lsphp84/bin/php -m | grep -Ei "mysqli|gd|mbstring|xml|zip|intl|imagick"
Use dnf search lsphp to see other versions. On RHEL-family systems the MySQL module is called -mysqlnd; on Debian and Ubuntu it is -mysql.
Start the server and set the WebAdmin password:
systemctl enable --now lsws
/usr/local/lsws/admin/misc/admpass.sh
Open the firewall for the web ports, and allow the admin console only from your own address (198.51.100.25 here):
firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.25" port port="7080" protocol="tcp" accept'
firewall-cmd --reload
The console is now at https://203.0.113.10:7080/ with a self-signed certificate. The default virtual host is called Example and listens on port 8088; you can leave it or delete it later.
Install MariaDB and create the database
AlmaLinux 10 AppStream ships MariaDB 10.11 as mariadb-server (10.11.18 when we checked).
dnf -y install mariadb-server
systemctl enable --now mariadb
mariadb-secure-installation
Create a database and user for WordPress. Use your own strong password:
mariadb <<'SQL'
CREATE DATABASE wp_example CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'wp_example'@'localhost' IDENTIFIED BY 'change-this-password';
GRANT ALL PRIVILEGES ON wp_example.* TO 'wp_example'@'localhost';
FLUSH PRIVILEGES;
SQL
Download WordPress and create the virtual host
The OpenLiteSpeed docs keep each virtual host in its own folder with conf, html and logs subfolders. Follow the same layout:
mkdir -p /usr/local/lsws/example.com/{conf,html,logs}
cd /tmp && curl -sO https://wordpress.org/latest.tar.gz
tar xzf latest.tar.gz -C /usr/local/lsws/example.com/html --strip-components=1
grep -E "^(user|group)" /usr/local/lsws/conf/httpd_config.conf
The last command shows the user and group OpenLiteSpeed runs PHP as. Give that account ownership of the site so WordPress can write uploads and updates (replace nobody:nobody with what the command printed):
chown -R nobody:nobody /usr/local/lsws/example.com/html
Now configure the site in the WebAdmin console:
- Server Configuration > External App > Add: type LSAPI, name
lsphp84, addressuds://tmp/lshttpd/lsphp84.sock, command/usr/local/lsws/lsphp84/bin/lsphp. Keep Max Connections and thePHP_LSAPI_CHILDRENenvironment value equal (the docs use 10 for both). - Virtual Hosts > Add: Virtual Host Name
example.com, Virtual Host Root$SERVER_ROOT/example.com, Config File$SERVER_ROOT/conf/vhosts/example.com/vhost.conf(the console offers to create it). - In that virtual host, General tab: Document Root
$VH_ROOT/html/, Domain Nameexample.com, Index Filesindex.php, index.html. - Script Handler tab: add suffix
php, handler type LiteSpeed SAPI, handlerlsphp84. - Rewrite tab: set Enable Rewrite and Auto Load from .htaccess to Yes.
- Listeners > Add: name
HTTP, IP Address ANY IPv4, port80. Under Virtual Host Mappings mapexample.comto the domainsexample.com, www.example.com. - Click Graceful Restart.
Browse to http://example.com/ and run the WordPress installer with the database details from the previous step.
Add HTTPS with Let’s Encrypt
EPEL 10 has certbot (4.2.0 when we checked). Use the webroot method so certbot never stops the web server, and restart OpenLiteSpeed after each renewal so it loads the new certificate:
dnf -y install certbot
certbot certonly --webroot -w /usr/local/lsws/example.com/html \
-d example.com -d www.example.com \
--deploy-hook "systemctl restart lsws"
Then add an HTTPS listener in WebAdmin: Listeners > Add, name HTTPS, IP ANY, port 443, Secure Yes. On its SSL tab set Private Key File to /etc/letsencrypt/live/example.com/privkey.pem, Certificate File to /etc/letsencrypt/live/example.com/fullchain.pem and Chained Certificate to Yes. Map the same virtual host on this listener and restart. Finally, set the WordPress and site URLs to https:// under Settings > General.
OpenLiteSpeed also has a built-in ACME feature that issues certificates for you. Use one method, not both.
Turn on LiteSpeed Cache and permalinks
- In WordPress, install and activate the LiteSpeed Cache plugin.
- Under Settings > Permalinks choose Post name and save. WordPress writes its rules to
.htaccess. - Restart OpenLiteSpeed so it loads the new .htaccess:
systemctl restart lsws. This restart is needed every time rewrite rules in .htaccess change.
EPEL 10 also packages wp-cli (2.12.0 when we checked) if you prefer to manage plugins and updates from the shell: dnf -y install wp-cli.
Check that it worked
systemctl status lsws --no-pager
curl -sI https://example.com/ | head -5
curl -s -o /dev/null -w "%{http_code}\n" https://example.com/sample-page/
/usr/local/lsws/lsphp84/bin/php -v
- The site loads over HTTPS without warnings and a pretty permalink returns 200.
- In WordPress, Tools > Site Health shows no missing required PHP modules.
- Port 7080 is not reachable from other addresses.
- A dry-run renewal works:
certbot renew --dry-run.
Common problems
- Permalinks return 404: rewrite is off, Auto Load from .htaccess is off, or OpenLiteSpeed was not restarted after WordPress wrote
.htaccess. - Browser downloads PHP files: the virtual host has no script handler for
php, or the external app name does not match. - 503 errors: check
/usr/local/lsws/logs/error.logand/usr/local/lsws/logs/stderr.log. A wrong LSPHP path or a missing module is the usual cause. - WordPress asks for FTP details on updates: the site files are not owned by the user OpenLiteSpeed runs PHP as.
- Error establishing a database connection: check the credentials in
wp-config.phpand that MariaDB is running. - Access denied in the audit log: AlmaLinux runs SELinux in enforcing mode; check
ausearch -m avc -ts recentbefore you change any policy.
Official documentation: OpenLiteSpeed: Install from repository · OpenLiteSpeed: Configuration · OpenLiteSpeed: PHP · OpenLiteSpeed: SSL
Related: LiteSpeed Cache WordPress cPanel: Recommended Settings · Harden SSH AlmaLinux 9: Secure Setup in 15 Minutes · InnoDB Tuning MariaDB 11/12: Shared Hosting Settings · SSL Certificate Checker · Security Headers Checker
See also: LiteSpeed vs OpenLiteSpeed for Hosting Servers: Which to Pick · Stuck lsphp Processes on cPanel LiteSpeed: Diagnose and Kill Safely · PHP-FPM Calculator: pm.max_children and Spare Servers
Frequently asked questions
Does OpenLiteSpeed support AlmaLinux 10?
Yes. The OpenLiteSpeed docs list CentOS 8, 9 and 10 including RHEL derivatives such as AlmaLinux, and the LiteSpeed repository has EL10 packages.
Which PHP version should I use with WordPress on OpenLiteSpeed?
Use a supported LSPHP build such as lsphp84. The EL10 repository also has lsphp83 and lsphp85.
Do I need to restart OpenLiteSpeed after changing .htaccess?
Yes. OpenLiteSpeed reads rewrite rules from .htaccess only after a restart, unlike LiteSpeed Enterprise.
Where is the OpenLiteSpeed admin panel?
The WebAdmin console listens on port 7080. Set its password with /usr/local/lsws/admin/misc/admpass.sh and restrict the port in the firewall.
Can I use the stock AlmaLinux PHP packages instead of LSPHP?
The OpenLiteSpeed docs configure PHP through LSAPI external apps that point at LSPHP binaries. Use LSPHP from the LiteSpeed repository.