Post Date: September 30, 2018
Last Updated: September 25, 2026
Introduction
Nginx is a lightweight, high-performance web server and reverse proxy commonly used for hosting websites, applications, APIs, and load-balanced services.
The original version of this article covered installing Nginx 1.15.4 on CentOS 7 using the Nginx repository. Since the original procedure was published, Nginx repository configurations, package signing practices, and Linux security requirements have evolved.
Prerequisites
Before starting, make sure you have:
- A CentOS 7 x86_64 server
- Root or
sudoaccess - Internet connectivity
- A configured hostname or server IP
firewalldenabled if you plan to use the local firewall- An existing application or website if Nginx will be used as a reverse proxy
Note: CentOS 7 is no longer supported. For production systems, migration to a supported operating system should be planned.
Step 1: Check the CentOS Version
First, verify the operating system version:
cat /etc/centos-release
You can also check the kernel and architecture:
uname -m uname -r
The original environment for this article is:
CentOS 7 x86_64
Step 2: Remove an Existing Nginx Package if Required
Before installing Nginx from the official repository, check whether Nginx is already installed:
nginx -v
If Nginx is already installed through another repository or package source, review the installation before replacing it.
You can check the installed RPM package with:
rpm -qa | grep nginx
If the existing installation is no longer required, remove it:
sudo yum remove nginx
Warning: Do not remove an existing Nginx installation on a production server until you have confirmed its configuration and dependencies.
Step 3: Create the Official Nginx Repository
Create the repository configuration:
sudo vi /etc/yum.repos.d/nginx.repo
For the Nginx mainline repository, add:
[nginx] name=nginx repo baseurl=http://nginx.org/packages/mainline/centos/$releasever/$basearch/ gpgcheck=1 enabled=1 gpgkey=https://nginx.org/keys/nginx_signing.key
Save the file and exit.
Mainline vs. Stable
Nginx provides two primary release tracks:
- Mainline – receives newer features and improvements first.
- Stable – focuses on a more conservative release stream.
For production environments, select the release stream according to your application’s compatibility and operational requirements rather than automatically choosing the newest package.
Security Note: The original article used
gpgcheck=0. That disables RPM signature verification and is not recommended. The updated configuration enables GPG verification.
Step 4: Clean the YUM Cache
Run:
sudo yum clean all
Then rebuild the package metadata:
sudo yum makecache
Verify that the Nginx repository is available:
yum repolist enabled | grep nginx
Step 5: Install Nginx
Install Nginx using YUM:
sudo yum install nginx
When prompted to confirm the installation, enter:
y
After installation, verify the installed version:
nginx -v
For additional build information:
nginx -V
Step 6: Test the Nginx Configuration
Before starting the service, validate the configuration:
sudo nginx -t
A successful result should indicate that the syntax is valid and the configuration test was successful.
This check is especially important before making configuration changes on production servers.
Step 7: Start Nginx
Start the Nginx service:
sudo systemctl start nginx
Check its status:
sudo systemctl status nginx
If the service starts successfully, Nginx should show an active status.
Step 8: Enable Nginx at Boot
To automatically start Nginx after a server reboot:
sudo systemctl enable nginx
Verify:
sudo systemctl is-enabled nginx
Expected output:
enabled
Step 9: Check the Listening Port
By default, Nginx listens for HTTP traffic on port 80.
Check the listening socket:
sudo ss -ltnp | grep ':80'
If ss is unavailable, you can use:
sudo netstat -lntp | grep ':80'
You should see Nginx listening on port 80.
Step 10: Allow HTTP Traffic Through the Firewall
On CentOS 7, firewalld may be enabled by default.
Check its status:
sudo systemctl status firewalld
To allow HTTP traffic:
sudo firewall-cmd --permanent --zone=public --add-service=http
If HTTPS will be used, also allow HTTPS:
sudo firewall-cmd --permanent --zone=public --add-service=https
Reload the firewall:
sudo firewall-cmd --reload
Verify the configuration:
sudo firewall-cmd --zone=public --list-services
You should see:
http https
if both services were added.
Important: Opening a firewall port does not automatically make the service accessible from the Internet. Cloud providers may also have external firewall rules, security groups, or network ACLs that need to allow the traffic.
Step 11: Test Nginx Locally
Test the web server directly from the server:
curl -I http://127.0.0.1
A successful response should return an HTTP status such as:
HTTP/1.1 200 OK
You can also test using the server’s IP address:
curl -I http://SERVER_IP
Replace SERVER_IP with the actual server IP address.
Step 12: Access Nginx from a Browser
Open the following URL:
http://SERVER_IP
Replace SERVER_IP with your server’s public IP address.
If DNS is configured, you can instead access the server using its hostname:
http://example.com
If Nginx is running correctly and the firewall allows the connection, the default Nginx welcome page should be displayed.
Nginx Configuration Location
The main Nginx configuration file installed from the official Nginx repository is generally:
/etc/nginx/nginx.conf
Additional configuration files are commonly located under:
/etc/nginx/conf.d/
You can inspect the complete active configuration with:
sudo nginx -T
This is useful when troubleshooting configuration inheritance, virtual hosts, and included configuration files.
Common Troubleshooting
Nginx Does Not Start
Check the service:
sudo systemctl status nginx
Check the system journal:
sudo journalctl -u nginx --no-pager -n 100
Test the configuration:
sudo nginx -t
Port 80 Is Already in Use
Check which process is using port 80:
sudo ss -ltnp | grep ':80'
A common cause is another web server such as Apache/httpd.
Check Apache:
sudo systemctl status httpd
If Apache is not required:
sudo systemctl stop httpd
To prevent it from starting automatically:
sudo systemctl disable httpd
Firewall Is Blocking the Connection
Check the active firewall rules:
sudo firewall-cmd --zone=public --list-all
Make sure HTTP is allowed:
sudo firewall-cmd --zone=public --list-services
If required:
sudo firewall-cmd --permanent --zone=public --add-service=http sudo firewall-cmd --reload
Cloud Firewall or Security Group Is Blocking Traffic
If the server is hosted on a cloud platform, verify the provider-level firewall or security group.
For HTTP access, TCP port 80 must be permitted.
For HTTPS access, TCP port 443 must be permitted.
The operating system firewall and cloud firewall are separate security layers.
Nginx Service Management Commands
The following commands are useful for day-to-day Nginx administration:
Start Nginx
sudo systemctl start nginx
Stop Nginx
sudo systemctl stop nginx
Restart Nginx
sudo systemctl restart nginx
Reload Nginx
Use reload when you want to apply configuration changes without unnecessarily stopping active connections:
sudo systemctl reload nginx
Check Status
sudo systemctl status nginx
Enable at Boot
sudo systemctl enable nginx
Security Considerations
Installing Nginx is only the first step in securing a web server.
For production environments, consider:
- Use HTTPS with a valid TLS certificate.
- Keep Nginx and the operating system patched where supported.
- Restrict unnecessary firewall ports.
- Use strong SSH authentication and disable unnecessary access.
- Monitor Nginx access and error logs.
- Use appropriate security headers.
- Protect administrative interfaces.
- Review file and directory permissions.
- Implement centralized monitoring and alerting.
- Maintain tested backups.
- Plan migration away from unsupported operating systems such as CentOS 7.
Nginx logs are typically available under:
/var/log/nginx/access.log /var/log/nginx/error.log
Configuration Summary
| Task | Command / Location |
|---|---|
| Nginx repository | /etc/yum.repos.d/nginx.repo |
| Install Nginx | sudo yum install nginx |
| Test configuration | sudo nginx -t |
| Start service | sudo systemctl start nginx |
| Enable at boot | sudo systemctl enable nginx |
| Check status | sudo systemctl status nginx |
| Check port 80 | sudo ss -ltnp | grep ':80' |
| Allow HTTP | firewall-cmd --permanent --add-service=http |
| Allow HTTPS | firewall-cmd --permanent --add-service=https |
| Nginx configuration | /etc/nginx/nginx.conf |
| Nginx logs | /var/log/nginx/ |
Conclusion
Nginx can be installed on CentOS 7 using the official Nginx repository rather than relying on the older packages available through the default CentOS repositories.
The updated process includes repository configuration, GPG verification, Nginx installation, configuration validation, service management, firewall configuration, and connectivity testing.
However, CentOS 7 is now end-of-life, so new production deployments should use a supported operating system. Existing CentOS 7 environments should be evaluated for migration to a supported Linux distribution.
FAQ
1. Is CentOS 7 still supported?
No. CentOS 7 reached End of Life on June 30, 2024. Existing systems should be evaluated for migration to a supported operating system.
2. Should I use Nginx Mainline or Stable?
The choice depends on your application requirements and operational policies. Mainline receives newer features earlier, while stable releases are generally preferred when a more conservative release stream is required.
3. Why is gpgcheck=1 recommended?
GPG verification allows YUM/RPM to verify that packages are signed by a trusted key. Disabling package signature verification is not recommended.
4. Why can’t I access Nginx from my browser?
Check the following:
- Nginx service status
- Nginx configuration
- Port 80 listening status
firewalld- Cloud firewall/security group
- DNS configuration
- Network connectivity
5. How do I verify the installed Nginx version?
Run:
nginx -v
6. Can Nginx listen on a port other than 80?
Yes. Nginx can be configured to listen on another port, such as 8080, by changing the appropriate listen directive in its configuration.
Related Articles
- Nginx configuration to enable ACME Challenge support on all HTTP virtual hosts
- Nginx missing sites-available directory in the Nginx configuration directory
Get Expert Nginx & Linux Server Support
Managing Nginx, Linux servers, firewalls, web applications, and production infrastructure can require careful configuration and ongoing monitoring. Our team can help with Nginx deployment, Linux server administration, security hardening, reverse proxy configuration, troubleshooting, monitoring, and performance optimization.