Webmin is a web-based administration tool for Linux servers. From a browser you can manage users, packages, services, cron jobs, firewall rules and configuration files without memorizing every command. In this tutorial you will install Webmin from its official APT repository on Ubuntu 24.04, restrict access to the admin port, replace the self-signed certificate with a Let's Encrypt one and use a few of its core modules.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS, for example a CubePath VPS, with at least 1 GB of RAM.
  • A non-root user with sudo privileges.
  • UFW enabled with SSH allowed (sudo ufw allow OpenSSH before sudo ufw enable).
  • For the TLS step: a domain name (called your_domain in this guide) with an A record pointing to your server's public IP (your_server_ip), and port 80 reachable from the internet.

Webmin also supports Debian 12 and Rocky Linux 9 with the same repository setup script. The package commands differ (dnf instead of apt, firewall-cmd instead of ufw), but the configuration steps are identical.

Step 1 - Adding the Webmin repository

Webmin is not in the Ubuntu archive. The project publishes a small script that adds its signed repository and GPG key for you. Download it first:

curl -o webmin-setup-repo.sh https://raw.githubusercontent.com/webmin/webmin/master/webmin-setup-repo.sh

Open it with less webmin-setup-repo.sh to review what it does: it installs the Webmin signing key and writes an APT source for download.webmin.com. Then run it:

sudo sh webmin-setup-repo.sh

Answer y when it asks to set up the repository. Confirm that APT now sees the package:

apt policy webmin
webmin:
  Installed: (none)
  Candidate: 2.xxx
  Version table:
     2.xxx 500
        500 https://download.webmin.com/download/newkey/repository stable/contrib amd64 Packages

Step 2 - Installing Webmin

Install the package together with its recommended dependencies, which include the Perl modules several modules rely on:

sudo apt install --install-recommends webmin

The package creates a systemd service called webmin and starts it. Check that it is running:

sudo systemctl status webmin
● webmin.service - Webmin server daemon
     Loaded: loaded (...; enabled; preset: enabled)
     Active: active (running) since ...

Webmin's built-in web server (miniserv) listens on TCP port 10000 with HTTPS enabled by default:

sudo ss -tlnp | grep 10000
LISTEN 0      4096         0.0.0.0:10000      0.0.0.0:*    users:(("miniserv.pl",pid=...,fd=5))

Step 3 - Restricting access to port 10000

Webmin has root-level control over the server, so it should not be open to the whole internet. Allow port 10000 only from the IP address you administer from (your_admin_ip):

sudo ufw allow from your_admin_ip to any port 10000 proto tcp

If your admin IP changes often, a safer alternative is to leave the port closed and reach Webmin through an SSH tunnel from your workstation:

ssh -L 10000:127.0.0.1:10000 your_user@your_server_ip

With the tunnel open, browse to https://localhost:10000. Verify the firewall rule:

sudo ufw status
To                         Action      From
--                         ------      ----
OpenSSH                    ALLOW       Anywhere
10000/tcp                  ALLOW       your_admin_ip

Step 4 - Logging in for the first time

Open https://your_server_ip:10000 in your browser. Until you complete Step 5 the certificate is self-signed, so the browser shows a warning that you have to accept once.

Webmin authenticates against the system accounts. On Ubuntu, where the root account has no password, log in with your sudo user and its password: Webmin grants full access to any user that can run all commands with sudo.

After logging in you land on the Dashboard, which shows the hostname, OS version, CPU, memory and disk usage, and pending package updates. The left menu groups the modules into categories such as System, Servers, Networking and Tools.

Step 5 - Using a Let's Encrypt certificate

Replace the self-signed certificate so that browsers trust the panel. Certbot's standalone mode needs port 80 open temporarily for the HTTP-01 challenge:

sudo apt install certbot
sudo ufw allow 80/tcp
sudo certbot certonly --standalone -d your_domain
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/your_domain/fullchain.pem
Key is saved at:         /etc/letsencrypt/live/your_domain/privkey.pem

Webmin's settings live in /etc/webmin/miniserv.conf. Open it:

sudo nano /etc/webmin/miniserv.conf

Find the existing keyfile= line and replace it, then add the certfile and extracas lines, so the block looks like this:

keyfile=/etc/letsencrypt/live/your_domain/privkey.pem
certfile=/etc/letsencrypt/live/your_domain/cert.pem
extracas=/etc/letsencrypt/live/your_domain/chain.pem

Restart Webmin to load the certificate:

sudo systemctl restart webmin

Certbot renews certificates automatically through its systemd timer, but Webmin only reads them at startup. Add a deploy hook so Webmin restarts after each successful renewal:

sudo sh -c 'printf "#!/bin/sh\nsystemctl restart webmin\n" > /etc/letsencrypt/renewal-hooks/deploy/webmin.sh'
sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/webmin.sh

Test renewal without issuing a real certificate:

sudo certbot renew --dry-run
Congratulations, all simulated renewals succeeded:
  /etc/letsencrypt/live/your_domain/fullchain.pem (success)

Now browse to https://your_domain:10000. The browser should show a valid certificate without warnings. Leave port 80 open, because standalone renewals need it every time Certbot renews the certificate.

Step 6 - Hardening the login

A few settings under Webmin > Webmin Configuration reduce the risk of brute-force attacks:

  • Authentication: keep Block hosts with more than 5 failed logins enabled and set a short Auto-logout period, for example 30 minutes.
  • IP Access Control: select Only allow from listed addresses and add your admin IP. This is a second layer on top of UFW and is stored as the allow= line in miniserv.conf.
  • Two-Factor Authentication: choose Google Authenticator as the provider, then enroll your user under Webmin > Webmin Users > Two-Factor Authentication. Webmin offers to install the required Perl module if it is missing.

Changing the port is also done in /etc/webmin/miniserv.conf with the port= and listen= lines. If you change it, update the UFW rule to match and restart the service.

Step 7 - Managing the server from Webmin

Try a few common tasks to confirm everything works:

  1. System > Software Package Updates: lists available updates and installs them with one click. It runs apt behind the scenes, so the result is the same as sudo apt upgrade.
  2. System > Bootup and Shutdown: shows every systemd unit with its state. Select a service and use Start, Stop or Restart.
  3. System > Users and Groups: create a user, set its shell and home directory, and add it to groups such as sudo.
  4. System > Scheduled Cron Jobs: create and edit cron jobs for any user.
  5. Tools > System Logs: read journal and log files from the browser.

To confirm that changes made in Webmin reach the system, create a test user in Users and Groups and check it from the terminal:

getent passwd testuser
testuser:x:1001:1001::/home/testuser:/bin/bash

Delete the test user when you are done.

Troubleshooting

The browser cannot connect to port 10000. Check that the service is running with sudo systemctl status webmin and that UFW allows your current IP with sudo ufw status. If your public IP changed, add a new rule.

Login fails with the correct password. Check sudo journalctl -u webmin and /var/webmin/miniserv.error. After several failed attempts Webmin blocks your IP for a while; wait or restart the service.

Webmin fails to start after editing miniserv.conf. A wrong certificate path is the usual cause. Confirm the files exist with sudo ls /etc/letsencrypt/live/your_domain/ and look at /var/webmin/miniserv.error for the exact message.

Conclusion

You installed Webmin from its official repository, limited access to the admin port, secured it with a trusted Let's Encrypt certificate and enabled login protections. From here you can add modules for the software you run, such as the Apache, Nginx or MySQL modules, or install Virtualmin on top of Webmin if you need to host websites and email for several domains. Keep Webmin up to date with the rest of the system using sudo apt upgrade.