Setting up SSL certificates in cPanel ensures your site loads over HTTPS, protecting visitor data and improving search engine rankings. Whether you're installing a free Let's Encrypt certificate through AutoSSL or uploading a commercial certificate, cPanel provides multiple methods to get SSL working on your domains. This guide walks through each installation method step by step, from initial access to verification.
Prerequisites
Before installing SSL certificates in cPanel, verify you have:
- Active cPanel account with login credentials
- Domain pointing to your server (A record or CNAME configured)
- Root or reseller access if enabling AutoSSL for multiple accounts
- Certificate files ready if installing a commercial certificate (CRT, KEY, and CA bundle)
- SSH access if troubleshooting or using command-line tools
Most shared hosting environments come with AutoSSL enabled by default, but VPS and dedicated server owners may need to configure it first.
Method 1: AutoSSL (Automatic Free Certificates)
AutoSSL is cPanel's automated certificate management system that provisions and renews free SSL certificates without manual intervention. Most cPanel installations use Let's Encrypt as the AutoSSL provider.
Step 1: Verify AutoSSL Is Enabled
- Log into WHM (Web Host Manager) as root
- Navigate to SSL/TLS → Manage AutoSSL
- Confirm AutoSSL is enabled and a provider is selected
- Check that your domain's hosting account appears in the enabled users list
If AutoSSL is disabled, enable it and select Let's Encrypt as the provider before proceeding.
Step 2: Run AutoSSL for Your Domain
From cPanel:
- Log into your cPanel account
- Scroll to the Security section
- Click SSL/TLS Status
- Find your domain in the list
- Click Run AutoSSL or wait for the next automatic check
AutoSSL runs automatically every night, but you can trigger immediate processing for new domains.
Step 3: Verify Domain Requirements
AutoSSL requires:
- Domain resolves to the server's IP address
- Port 80 accessible for HTTP validation
- No conflicting CAA DNS records blocking Let's Encrypt
- Valid domain configuration in Apache/cPanel
If AutoSSL fails, check the error message in SSL/TLS Status. Common issues include DNS propagation delays and firewall rules blocking validation requests.
Step 4: Confirm Certificate Installation
- Return to SSL/TLS Status in cPanel
- Look for a green checkmark next to your domain
- Certificate details show issuer, expiration date, and covered domains
- Visit your site at
https://yourdomain.comto confirm
AutoSSL certificates renew automatically before expiration, typically with 30 days remaining.
Method 2: Let's Encrypt Manual Installation
If AutoSSL isn't available or you prefer manual control, install Let's Encrypt certificates directly through cPanel's SSL interface.
Step 1: Generate Let's Encrypt Certificate
From cPanel:
- Navigate to Security → SSL/TLS
- Click Manage SSL sites
- Scroll to the domain you want to secure
- Look for Browse Certificates or Issue a new certificate
- Select Let's Encrypt if available as an option
Alternatively, use the command line with Certbot if you have SSH access:
sudo certbot certonly --webroot -w /home/username/public_html -d yourdomain.com -d www.yourdomain.com
Replace username with your cPanel username and adjust the domain names as needed.
Step 2: Locate Certificate Files
If you used Certbot, certificates are stored in:
/etc/letsencrypt/live/yourdomain.com/
You'll need:
cert.pem- The certificateprivkey.pem- The private keychain.pem- The CA bundle
Step 3: Install Through cPanel
- In cPanel, go to Security → SSL/TLS
- Click Manage SSL sites
- Select your domain from the dropdown
- Paste certificate contents into the appropriate fields:
- Certificate (CRT): contents of
cert.pem- Private Key (KEY): contents ofprivkey.pem- Certificate Authority Bundle (CABUNDLE): contents ofchain.pem - Click Install Certificate
cPanel validates the certificate matches the private key before installation.
Step 4: Set Up Renewal
Let's Encrypt certificates expire after 90 days. Create a cron job for automatic renewal:
0 3 * * * certbot renew --quiet --deploy-hook "/scripts/autossl_check --all"
This runs renewal checks daily at 3 AM and triggers cPanel to update installed certificates when renewed.
Method 3: Commercial SSL Certificate Installation
Commercial certificates from providers like Sectigo, DigiCert, or GlobalSign offer extended validation options and higher warranty coverage.
Step 1: Generate Certificate Signing Request (CSR)
- In cPanel, navigate to Security → SSL/TLS
- Click Generate, view, or delete SSL certificate signing requests
- Fill in certificate details: - Domain: yourdomain.com - City, State, Country: your organization's location - Company: legal entity name - Email: administrative contact
- Click Generate
- Copy the generated CSR text
cPanel automatically generates and stores the matching private key.
Step 2: Purchase and Validate Certificate
- Submit the CSR to your SSL provider during purchase
- Complete domain validation (email, DNS, or HTTP file upload)
- Wait for certificate issuance
- Download the certificate files from your provider
You should receive a certificate file (CRT) and CA bundle. The private key remains on your server from CSR generation.
Step 3: Install the Certificate
- Return to Security → SSL/TLS in cPanel
- Click Manage SSL sites
- Select your domain
- Upload or paste: - Certificate (CRT): provided by SSL vendor - Private Key (KEY): automatically filled if you used cPanel's CSR - Certificate Authority Bundle (CABUNDLE): intermediate certificates from vendor
- Click Install Certificate
cPanel automatically associates the certificate with your domain.
Step 4: Verify Chain and Configuration
Test the installation:
openssl s_client -connect yourdomain.com:443 -servername yourdomain.com
Check that the full certificate chain appears and the handshake completes successfully. You can also use online SSL checkers to verify proper installation.
Post-Installation Configuration
After installing any SSL certificate, complete these additional steps to ensure proper HTTPS operation.
Force HTTPS Redirects
Create or edit .htaccess in your document root:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
This redirects all HTTP traffic to HTTPS automatically.
Update WordPress Site URL
For WordPress sites:
- Log into WordPress admin
- Go to Settings → General
- Update both WordPress Address and Site Address to use
https:// - Save changes
Alternatively, update via wp-config.php:
define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');
Enable HSTS (Optional)
Add HTTP Strict Transport Security header to force HTTPS at the browser level. In .htaccess:
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Or in cPanel's Security → Security Policy section if available.
Check Mixed Content
Visit your site and open browser developer tools (F12). Check the Console tab for mixed content warnings indicating resources loaded over HTTP. Update hardcoded HTTP URLs to HTTPS or use protocol-relative URLs (//example.com/resource).
Troubleshooting Common Issues
AutoSSL Fails with Domain Validation Error
Check DNS resolution:
dig +short yourdomain.com
Ensure the result matches your server's IP address. DNS propagation can take up to 48 hours. Also verify port 80 is accessible from external networks.
Certificate Installed But Site Shows Not Secure
Review certificate coverage. If you installed SSL for yourdomain.com but visitors access www.yourdomain.com, you need a certificate covering both. Most certificates include both root and www subdomains, but verify in cPanel's SSL/TLS Status.
Private Key Doesn't Match Certificate
This error means the certificate was issued for a different CSR. Verify you're using the private key that corresponds to the CSR submitted to your certificate authority. If using a commercial certificate, regenerate the CSR in cPanel and reissue the certificate.
Certificate Chain Incomplete
Browsers may show warnings if intermediate certificates are missing. Ensure the CA Bundle field contains all intermediate certificates provided by your SSL vendor. Let's Encrypt's chain.pem includes required intermediates automatically.
AutoSSL Renewal Fails
Check that your domain's DNS hasn't changed and that Apache configuration remains valid. Review AutoSSL logs in WHM under SSL/TLS → Manage AutoSSL → View AutoSSL Log. Failed renewals often indicate DNS issues or CAA record restrictions.
Verifying SSL Installation
After completing installation and configuration, verify everything works correctly:
- Browser test: Visit
https://yourdomain.comand check for padlock icon - Certificate details: Click the padlock to view certificate information
- Online SSL checkers: Use tools to verify certificate chain and configuration
- Different browsers: Test in Chrome, Firefox, and Safari to ensure compatibility
- Mobile devices: Check that mobile browsers show secure connection
When testing, use incognito or private browsing mode to avoid cached redirects or certificate data.
Managing Multiple Domains
For accounts hosting multiple domains:
- Each domain requires its own SSL certificate or a wildcard certificate
- AutoSSL can secure all domains simultaneously if enabled
- Check SSL/TLS Status regularly to catch domains needing renewal
- Use WHM's SSL/TLS → Install an SSL Certificate on a Domain for batch operations
- Consider wildcard certificates (
*.yourdomain.com) for numerous subdomains
Wildcard certificates require DNS validation and aren't available through AutoSSL's default HTTP validation method.
Conclusion
Installing SSL certificates in cPanel ranges from fully automated with AutoSSL to manual management of commercial certificates. AutoSSL provides the simplest path for most sites, handling both initial installation and renewal without intervention. Commercial certificates remain valuable for sites requiring extended validation or specific warranty coverage. Regardless of method, verify your installation thoroughly, configure HTTPS redirects, and monitor for renewal to maintain continuous security. With SSL properly configured, your site gains both security and the SEO benefits of HTTPS, providing a foundation for trusted visitor interactions.
