Skip to content
Back to Blog
SSL & Security10 min read

Install SSL in cPanel: Step-by-Step Setup Guide (2026)

Learn how to install SSL certificates in cPanel with this complete walkthrough, covering AutoSSL, Let's Encrypt, and commercial certificate installation methods.

Written by Abdul AbrorTechnical Hosting Support Engineer
Install SSL in cPanel: Step-by-Step Setup Guide (2026)
On this page

Setting up SSL certificates in cPanel ensures your site loads over HTTPS, protecting visitor data and improving search engine rankings. Whether you're installing a free Let's Encrypt certificate through AutoSSL or uploading a commercial certificate, cPanel provides multiple methods to get SSL working on your domains. This guide walks through each installation method step by step, from initial access to verification.

Prerequisites

Before installing SSL certificates in cPanel, verify you have:

  • Active cPanel account with login credentials
  • Domain pointing to your server (A record or CNAME configured)
  • Root or reseller access if enabling AutoSSL for multiple accounts
  • Certificate files ready if installing a commercial certificate (CRT, KEY, and CA bundle)
  • SSH access if troubleshooting or using command-line tools

Most shared hosting environments come with AutoSSL enabled by default, but VPS and dedicated server owners may need to configure it first.

Method 1: AutoSSL (Automatic Free Certificates)

AutoSSL is cPanel's automated certificate management system that provisions and renews free SSL certificates without manual intervention. Most cPanel installations use Let's Encrypt as the AutoSSL provider.

Step 1: Verify AutoSSL Is Enabled

  1. Log into WHM (Web Host Manager) as root
  2. Navigate to SSL/TLS → Manage AutoSSL
  3. Confirm AutoSSL is enabled and a provider is selected
  4. Check that your domain's hosting account appears in the enabled users list

If AutoSSL is disabled, enable it and select Let's Encrypt as the provider before proceeding.

Step 2: Run AutoSSL for Your Domain

From cPanel:

  1. Log into your cPanel account
  2. Scroll to the Security section
  3. Click SSL/TLS Status
  4. Find your domain in the list
  5. Click Run AutoSSL or wait for the next automatic check

AutoSSL runs automatically every night, but you can trigger immediate processing for new domains.

Step 3: Verify Domain Requirements

AutoSSL requires:

  • Domain resolves to the server's IP address
  • Port 80 accessible for HTTP validation
  • No conflicting CAA DNS records blocking Let's Encrypt
  • Valid domain configuration in Apache/cPanel

If AutoSSL fails, check the error message in SSL/TLS Status. Common issues include DNS propagation delays and firewall rules blocking validation requests.

Step 4: Confirm Certificate Installation

  1. Return to SSL/TLS Status in cPanel
  2. Look for a green checkmark next to your domain
  3. Certificate details show issuer, expiration date, and covered domains
  4. Visit your site at https://yourdomain.com to confirm

AutoSSL certificates renew automatically before expiration, typically with 30 days remaining.

Method 2: Let's Encrypt Manual Installation

If AutoSSL isn't available or you prefer manual control, install Let's Encrypt certificates directly through cPanel's SSL interface.

Step 1: Generate Let's Encrypt Certificate

From cPanel:

  1. Navigate to Security → SSL/TLS
  2. Click Manage SSL sites
  3. Scroll to the domain you want to secure
  4. Look for Browse Certificates or Issue a new certificate
  5. Select Let's Encrypt if available as an option

Alternatively, use the command line with Certbot if you have SSH access:

sudo certbot certonly --webroot -w /home/username/public_html -d yourdomain.com -d www.yourdomain.com

Replace username with your cPanel username and adjust the domain names as needed.

Step 2: Locate Certificate Files

If you used Certbot, certificates are stored in:

/etc/letsencrypt/live/yourdomain.com/

You'll need:

  • cert.pem - The certificate
  • privkey.pem - The private key
  • chain.pem - The CA bundle

Step 3: Install Through cPanel

  1. In cPanel, go to Security → SSL/TLS
  2. Click Manage SSL sites
  3. Select your domain from the dropdown
  4. Paste certificate contents into the appropriate fields: - Certificate (CRT): contents of cert.pem - Private Key (KEY): contents of privkey.pem - Certificate Authority Bundle (CABUNDLE): contents of chain.pem
  5. Click Install Certificate

cPanel validates the certificate matches the private key before installation.

Step 4: Set Up Renewal

Let's Encrypt certificates expire after 90 days. Create a cron job for automatic renewal:

0 3 * * * certbot renew --quiet --deploy-hook "/scripts/autossl_check --all"

This runs renewal checks daily at 3 AM and triggers cPanel to update installed certificates when renewed.

Method 3: Commercial SSL Certificate Installation

Commercial certificates from providers like Sectigo, DigiCert, or GlobalSign offer extended validation options and higher warranty coverage.

Step 1: Generate Certificate Signing Request (CSR)

  1. In cPanel, navigate to Security → SSL/TLS
  2. Click Generate, view, or delete SSL certificate signing requests
  3. Fill in certificate details: - Domain: yourdomain.com - City, State, Country: your organization's location - Company: legal entity name - Email: administrative contact
  4. Click Generate
  5. Copy the generated CSR text

cPanel automatically generates and stores the matching private key.

Step 2: Purchase and Validate Certificate

  1. Submit the CSR to your SSL provider during purchase
  2. Complete domain validation (email, DNS, or HTTP file upload)
  3. Wait for certificate issuance
  4. Download the certificate files from your provider

You should receive a certificate file (CRT) and CA bundle. The private key remains on your server from CSR generation.

Step 3: Install the Certificate

  1. Return to Security → SSL/TLS in cPanel
  2. Click Manage SSL sites
  3. Select your domain
  4. Upload or paste: - Certificate (CRT): provided by SSL vendor - Private Key (KEY): automatically filled if you used cPanel's CSR - Certificate Authority Bundle (CABUNDLE): intermediate certificates from vendor
  5. Click Install Certificate

cPanel automatically associates the certificate with your domain.

Step 4: Verify Chain and Configuration

Test the installation:

openssl s_client -connect yourdomain.com:443 -servername yourdomain.com

Check that the full certificate chain appears and the handshake completes successfully. You can also use online SSL checkers to verify proper installation.

Post-Installation Configuration

After installing any SSL certificate, complete these additional steps to ensure proper HTTPS operation.

Force HTTPS Redirects

Create or edit .htaccess in your document root:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

This redirects all HTTP traffic to HTTPS automatically.

Update WordPress Site URL

For WordPress sites:

  1. Log into WordPress admin
  2. Go to Settings → General
  3. Update both WordPress Address and Site Address to use https://
  4. Save changes

Alternatively, update via wp-config.php:

define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');

Enable HSTS (Optional)

Add HTTP Strict Transport Security header to force HTTPS at the browser level. In .htaccess:

Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

Or in cPanel's Security → Security Policy section if available.

Check Mixed Content

Visit your site and open browser developer tools (F12). Check the Console tab for mixed content warnings indicating resources loaded over HTTP. Update hardcoded HTTP URLs to HTTPS or use protocol-relative URLs (//example.com/resource).

Troubleshooting Common Issues

AutoSSL Fails with Domain Validation Error

Check DNS resolution:

dig +short yourdomain.com

Ensure the result matches your server's IP address. DNS propagation can take up to 48 hours. Also verify port 80 is accessible from external networks.

Certificate Installed But Site Shows Not Secure

Review certificate coverage. If you installed SSL for yourdomain.com but visitors access www.yourdomain.com, you need a certificate covering both. Most certificates include both root and www subdomains, but verify in cPanel's SSL/TLS Status.

Private Key Doesn't Match Certificate

This error means the certificate was issued for a different CSR. Verify you're using the private key that corresponds to the CSR submitted to your certificate authority. If using a commercial certificate, regenerate the CSR in cPanel and reissue the certificate.

Certificate Chain Incomplete

Browsers may show warnings if intermediate certificates are missing. Ensure the CA Bundle field contains all intermediate certificates provided by your SSL vendor. Let's Encrypt's chain.pem includes required intermediates automatically.

AutoSSL Renewal Fails

Check that your domain's DNS hasn't changed and that Apache configuration remains valid. Review AutoSSL logs in WHM under SSL/TLS → Manage AutoSSL → View AutoSSL Log. Failed renewals often indicate DNS issues or CAA record restrictions.

Verifying SSL Installation

After completing installation and configuration, verify everything works correctly:

  1. Browser test: Visit https://yourdomain.com and check for padlock icon
  2. Certificate details: Click the padlock to view certificate information
  3. Online SSL checkers: Use tools to verify certificate chain and configuration
  4. Different browsers: Test in Chrome, Firefox, and Safari to ensure compatibility
  5. Mobile devices: Check that mobile browsers show secure connection

When testing, use incognito or private browsing mode to avoid cached redirects or certificate data.

Managing Multiple Domains

For accounts hosting multiple domains:

  1. Each domain requires its own SSL certificate or a wildcard certificate
  2. AutoSSL can secure all domains simultaneously if enabled
  3. Check SSL/TLS Status regularly to catch domains needing renewal
  4. Use WHM's SSL/TLS → Install an SSL Certificate on a Domain for batch operations
  5. Consider wildcard certificates (*.yourdomain.com) for numerous subdomains

Wildcard certificates require DNS validation and aren't available through AutoSSL's default HTTP validation method.

Conclusion

Installing SSL certificates in cPanel ranges from fully automated with AutoSSL to manual management of commercial certificates. AutoSSL provides the simplest path for most sites, handling both initial installation and renewal without intervention. Commercial certificates remain valuable for sites requiring extended validation or specific warranty coverage. Regardless of method, verify your installation thoroughly, configure HTTPS redirects, and monitor for renewal to maintain continuous security. With SSL properly configured, your site gains both security and the SEO benefits of HTTPS, providing a foundation for trusted visitor interactions.

FAQ

Does installing SSL affect site performance?

SSL adds minimal overhead. Modern servers handle TLS efficiently, and HTTPS enables HTTP/2, which often improves performance compared to HTTP/1.1.

Can I use the same SSL certificate on multiple domains?

Only if you purchase a multi-domain (SAN) certificate that explicitly lists all domains. Standard certificates cover only the specified domain and typically www subdomain.

What happens if my SSL certificate expires?

Browsers display security warnings, preventing most visitors from accessing your site. AutoSSL renews automatically, but commercial certificates require manual renewal and reinstallation.

Do I need a dedicated IP for SSL in cPanel?

No. Modern cPanel installations support SNI (Server Name Indication), allowing multiple SSL certificates on shared IP addresses. SNI works with all current browsers.

Can I install SSL on a subdomain?

Yes. Follow the same process but specify the subdomain instead of the root domain. AutoSSL secures all configured subdomains automatically.

Why does my site still show mixed content warnings after installing SSL?

Your pages reference resources (images, scripts, stylesheets) over HTTP. Update these URLs to HTTPS or use protocol-relative URLs to resolve the warnings.