All hosting help

Install a Let’s Encrypt certificate

Request a certificate through cPanel AutoSSL and investigate validation failures.

Updated September 2026

Web hosting plans include Let’s Encrypt certificates. Use cPanel’s SSL/TLS Status to check issuance, renewals and validation errors for hosted domains.

How AutoSSL works

AutoSSL runs automatically: every domain you add to cPanel triggers an HTTP challenge. Let's Encrypt requests a specific file at http://yourdomain.com/.well-known/acme-challenge/... and if it sees the expected response, it issues a 90-day certificate. AutoSSL renews 30 days before expiry, also automatically.

For the challenge to succeed, three things must be true:

  • The domain's A record points to your Omega Digital server IP
  • Port 80 on the server is reachable and not redirecting in a way that breaks the challenge path
  • The domain is listed in the Domains section of cPanel (it usually is, automatically)

Check current status

  1. In cPanel, open SSL/TLS Status under the Security section.
  2. You will see every domain and subdomain on the account with a green, yellow, or red status dot.
  3. Green: valid certificate, renews automatically.
  4. Yellow: AutoSSL is trying, not yet issued.
  5. Red: issuance failed. Click the domain for the specific error.

Request a certificate

  1. Open cPanel → SSL/TLS Status.
  2. Tick the domains you want covered.
  3. Click Run AutoSSL.
  4. Wait 1-5 minutes. Refresh the page.
# Force issuance from SSH (faster feedback than the UI)
uapi --user=cpuser SSL start_autossl_check

# Tail the AutoSSL log
tail -f /var/cpanel/logs/autossl.log

What happens when validation fails

Read the error shown in SSL/TLS Status. Common validation errors include:

ErrorCauseFix
DNS does not resolve to the serverA record points elsewhereUpdate A record at DNS provider
HTTP returned non-200 for challenge path.htaccess redirects everything to HTTPSExempt /.well-known/acme-challenge/ in .htaccess
CAA record forbids Let's EncryptOld CAA record restricts CAsAdd CAA 0 issue 'letsencrypt.org' or delete the existing CAA
# In .htaccess : exclude the challenge path from redirects
RewriteEngine On
RewriteCond %{REQUEST_URI} !^/\.well-known/acme-challenge/
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Cloudflare proxy and AutoSSL

If Cloudflare is proxying (orange cloud), Let's Encrypt sees Cloudflare's IP, not ours. AutoSSL still works because the challenge passes through Cloudflare, but the HTTP challenge must reach the origin without being blocked. Two good fixes:

  1. Temporarily set the record to DNS only for certificate issuance, then restore the proxy setting.
  2. Better: use a Cloudflare Origin certificate instead of AutoSSL (15-year validity, no HTTP validation needed).

When to use a paid certificate

Let's Encrypt is the right default. The narrow cases where paid still makes sense:

  • Extended Validation (EV) certificate with organization name in browsers. Rarely matters now since Chrome no longer shows it.
  • Warranty coverage for large e-commerce liability
  • Wildcard certificate for a very large subdomain fan-out where you want a single-cert deployment (Let's Encrypt wildcards work but require DNS challenge)
  • Device/embedded systems that don't trust Let's Encrypt's ISRG Root X1 (extremely rare in 2026)

Verify the certificate

# Show certificate details
echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null \
  | openssl x509 -noout -subject -issuer -dates

# Expected:
# subject=CN = yourdomain.com
# issuer=C = US, O = Let's Encrypt, CN = R3
# notBefore=Apr  1 12:00:00 2026 GMT
# notAfter=Jun 30 12:00:00 2026 GMT

Common issues

  • Certificate issued but browser still shows insecure. Usually a mixed-content issue: some image or script loaded over http://. See the force-HTTPS article.
  • AutoSSL disabled per-domain. Under Domains, each domain has a per-domain toggle. Confirm it's on.
  • Rate limits. Let's Encrypt allows 50 certificates per registered domain per week. If you're bulk-provisioning subdomains, batch carefully.
  • Unused domain. Remove a domain from cPanel if it no longer belongs to the hosting account and no longer needs a certificate there.

Contact support

Email [email protected] with the exact error from SSL/TLS Status.

Related reading