SSL Certificates in cPanel¶
An SSL certificate secures the connection between a website and the user's browser.
When the certificate is configured correctly, the website is available at:
instead of:
In cPanel, you can:
- check whether a domain has an active SSL certificate,
- run AutoSSL,
- install your own certificate,
- add a
CRTcertificate, - add a private
KEY, - add a
CABUNDLEcertificate chain, - check the certificate expiration date,
- replace an existing certificate.
1. Simplest option — AutoSSL¶
In most cases, you do not need to buy or manually upload a certificate.
cPanel can automatically issue and renew an SSL certificate using:
AutoSSL
To check SSL for a domain, after logging in to cPanel go to:
Security → SSL/TLS Status
You will see a list of domains and subdomains assigned to the account.
2. Checking SSL status¶
In:
Security → SSL/TLS Status
check your domain.
Example:
If the domain is shown as properly secured, the SSL certificate is active.
If the domain does not have a certificate, you can try running AutoSSL.
3. Running AutoSSL¶
In:
Security → SSL/TLS Status
select the domain for which you want to issue a certificate.
Then click:
Run AutoSSL
cPanel will try to:
- validate the domain,
- issue a certificate,
- install it on the server.
When the process is complete, check the domain status again.
4. Requirements for AutoSSL to issue a certificate¶
The domain must point correctly to the hosting service.
This usually means that the domain's DNS:
record points to the correct server IP address.
Example:
If you use:
that hostname should also point correctly to the hosting service.
If the domain points to another server, AutoSSL may not be able to confirm that the domain belongs to this hosting account.
5. Certificate works for the domain but not for www¶
The certificate should include all hostnames you use.
These are usually:
If:
works correctly, but:
shows a certificate error, check:
- the DNS record for
www, - the status of
www.domena.plin SSL/TLS Status, - whether the certificate includes
www.domena.pl.
Manually installing your own SSL certificate¶
If you have a certificate from an external provider, you can install it manually.
You will usually need:
that is:
6. What CRT, KEY, and CABUNDLE mean¶
CRT¶
This is the SSL certificate issued for the domain.
It may look like:
KEY¶
This is the private key corresponding to the certificate.
It may look like:
The private key is confidential.
Never publish or send the private key to anyone who should not have access to it.
A certificate cannot be installed correctly without its matching private key.
CABUNDLE¶
This is the intermediate certificate chain of the Certificate Authority.
It may look like:
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
In many cases, cPanel can automatically retrieve the correct CA Bundle, but if your certificate provider supplied a CABUNDLE, it is best to use the provided file.
7. Installing your own certificate¶
After logging in to cPanel, go to:
Security → SSL/TLS
Then select:
Manage SSL Sites
In newer cPanel versions, the options may be presented under a combined SSL/TLS Certificates view, but the certificate installation function remains available in the SSL/TLS section.
8. Select the domain¶
In the certificate installation section, select the domain.
Example:
Make sure the correct domain is selected.
9. Paste the CRT certificate¶
In:
Certificate (CRT)
paste the entire certificate.
Example:
Do not remove:
or:
10. Paste the private key¶
In:
Private Key (KEY)
paste the private key corresponding to the certificate.
Example:
The certificate and private key must form a matching pair.
You cannot use a random private key from another certificate.
11. Add the CABUNDLE¶
In:
Certificate Authority Bundle (CABUNDLE)
paste the certificate chain provided by the certificate issuer.
If cPanel fills this field automatically, you usually do not need to change it.
12. Install the certificate¶
After providing:
click:
Install Certificate
cPanel will report whether the installation was successful.
Uploading a certificate and key separately¶
cPanel also allows you to store the certificate and private key before assigning them to a domain.
13. Adding a CRT certificate¶
Go to:
Security → SSL/TLS
Then select the section related to:
Certificates (CRT)
There you can:
- paste a certificate,
- upload a certificate file,
- save the certificate on the account.
Adding the CRT to the certificate store alone does not mean that it has been assigned to a website.
You still need to install it for a specific domain.
14. Adding a private key¶
Go to:
Security → SSL/TLS
and select:
Private Keys (KEY)
There you can:
- paste an existing private key,
- upload a private key file,
- manage keys stored on the account.
Do not remove a private key unless you are sure it is not used by an active certificate.
CSR — ordering your own certificate¶
15. What is a CSR?¶
If you buy a certificate from an external provider, they may ask for a:
or:
Certificate Signing Request
A CSR contains information such as:
- the domain name,
- information required to issue the certificate,
- the public key.
A CSR does not contain the private key.
16. Generating a CSR in cPanel¶
Go to:
Security → SSL/TLS
then select:
Certificate Signing Requests (CSR)
Enter the required information, especially the domain name.
Example:
After generating the request, you will receive the:
and the server will create a:
Send the CSR to the certificate provider.
Do not send the private key.
Checking the certificate¶
17. How to check whether SSL works¶
After installation, open:
If the browser does not show a certificate warning, the SSL connection is working.
Also check:
if you use the www version.
18. Checking the expiration date¶
In cPanel, you can check the certificate expiration date in:
Security → SSL/TLS
or:
Security → SSL/TLS Status
AutoSSL certificates are renewed automatically as long as the domain can still be validated correctly.
Common problems¶
19. AutoSSL cannot issue a certificate¶
Check:
- whether the domain points to the correct server,
- whether the
Arecord is correct, - whether
wwwalso points to the correct server, - whether DNS propagation has completed,
- whether the domain is correctly added to the hosting account.
If the domain has CAA records, they may restrict which Certificate Authorities are allowed to issue a certificate.
20. Error: certificate does not match the key¶
If cPanel reports that the certificate does not match the private key, it means that:
and:
do not form a matching pair.
You must use the private key that was created with the CSR used to order that certificate.
21. I have the certificate but not the private key¶
The:
certificate alone is not enough.
You also need the matching:
If the private key has been lost, you usually need to:
- generate a new private key and CSR,
- reissue the certificate with the provider.
22. The certificate works, but the website still opens over HTTP¶
SSL does not always automatically redirect:
to:
If the website still opens over HTTP, you may need to enable HTTPS redirection in the domain settings or in the application itself.
Depending on the configuration, cPanel may provide:
Force HTTPS Redirect
under:
Domains
23. The website shows warnings after enabling HTTPS¶
If the certificate is valid but the browser still shows warnings, the website may be loading some resources over:
instead of:
This may affect:
- images,
- CSS stylesheets,
- JavaScript files.
This is called:
Mixed Content
In that case, update the resource URLs in the website or application.
Simplest procedure — AutoSSL¶
If you simply want to enable SSL for your domain:
- Log in to cPanel.
- Go to:
Security → SSL/TLS Status
- Find your domain.
- Select it.
- Click:
Run AutoSSL
- Wait for the operation to complete.
- Open:
- Check that the website works.
Done.
Simplest procedure — your own certificate¶
If you have your own certificate:
- Log in to cPanel.
- Go to:
Security → SSL/TLS → Manage SSL Sites
- Select the domain.
- Paste:
- Paste:
- Add:
if required.
- Click:
Install Certificate
- Open:
- Check that the website works.
Done.
Important¶
The private:
is confidential information.
Do not publish it, include it in public support tickets, or send it to anyone who should not have access to the certificate.
If you are not sure whether the domain is configured correctly or which certificate should be installed, contact Cloud4You technical support.