Manage AutoSSL
Home › SSL/TLS › Manage AutoSSL
The AutoSSL feature provides free SSL certificates for your users' domains. The system will periodically inspect users' installed certificates and replace those that are about to expire or that are insufficient to provide a baseline level of security. Users who do not have the "autossl" feature will not receive the free certificates.
Current Provider: Let's Encrypt™
Provider Account ID: https://acme-v02.api.letsencrypt.org/acme/acct/3158690191
Manage UsersAutoSSL Providers
Choose an AutoSSL provider: Show/Hide Details
This interface uses the following parameters to calculate the usability score: DCV Methods, Domains per Certificate, Average Delivery Time, Maximum Number of Redirects, and Wildcard Support. Click here to view details.
Terms of Service
To use Let's Encrypt™ as the AutoSSL provider, accept their terms of service:
https://letsencrypt.org/documents/LE-SA-v1.7-June-04-2026.pdf
Custom ACME
NEWAllow your customers to use their own ACME-compatible Certificate Authority for SSL automation in cPanel. Useful for customers who hold their own commercial CA accounts (Sectigo SCM, GlobalSign Atlas, DigiCert, regional CAs, internal PKI), or for partners reselling certificates from a CA they have a direct relationship with.
Customers configure their CA credentials (Directory URL, EAB Key ID, EAB HMAC) directly in cPanel. cPanel automates issuance and renewal; the customer's CA bills them directly. cPanel does not handle billing, certificate sales, or commercial terms for this option.
Manage AutoSSL → Logs
Home › SSL/TLS › Manage AutoSSL › Logs
AutoSSL Logs
Username filter applies to Custom ACME logs only.
Select a log to view:
Manage AutoSSL → Manage Users
Home › SSL/TLS › Manage AutoSSL › Manage Users
Configure AutoSSL for Users on the Server
Showing 1–5 of 5 items
Enable AutoSSL
Selected users:
Manage SSL Hosts
Server › SSL/TLS › Manage SSL Hosts
Installed SSL Hosts
| Domains | IP Address | IP Address Type | Is Primary Website on IP Address? | Is SNI Required? | Document Root | Owner | Issuer | Expires | Key Type | Actions |
|---|---|---|---|---|---|---|---|---|---|---|
| acme-corp.org www.acme-corp.org mail.acme-corp.org | 10.0.0.121 | Shared | Yes | No | /home/adminostesv23/public_html | adminostesv23 | Let's Encrypt | 5/30/2027 | RSA | Delete Make Primary |
| shop.acme-corp.org api.acme-corp.org | 10.0.0.121 | Shared | No | Yes | /home/adminostesv23/public_html/shop | adminostesv23 |
Sectigo CA Limited Custom ACME |
7/30/2026 | RSA | Delete Make Primary |
| blog.acme-corp.org | 10.0.0.121 | Shared | No | Yes | /home/adminostesv23/public_html/blog | adminostesv23 | Self Signed | 6/20/2026 | RSA | Delete Make Primary |
| gamenexa.com www.gamenexa.com | 10.0.0.122 | Shared | Yes | No | /home/gamenexa/public_html | gamenexa | Let's Encrypt | 8/4/2026 | ECC | Delete Make Primary |
| store.gamenexa.com | 10.0.0.122 | Shared | No | Yes | /home/gamenexa/public_html/store | gamenexa |
Sectigo CA Limited Custom ACME |
9/15/2026 | RSA | Delete Make Primary |
| blueterra.io www.blueterra.io | 10.0.0.123 | Shared | Yes | No | /home/customer3/public_html | customer3 | Let's Encrypt | 7/12/2026 | RSA | Delete Make Primary |
| app.blueterra.io | 10.0.0.123 | Shared | No | Yes | /home/customer3/public_html/app | customer3 |
Sectigo CA Limited Custom ACME |
8/22/2026 | ECC | Delete Make Primary |
Showing 4 domain groups
| Domain | Certificate | Issuer | Expiry | Actions | |
|---|---|---|---|---|---|
| hopkinslaw.net Primary | ✓ Let's Encrypt | Let's Encrypt | Aug 12, 2026 | View Certificate Secure this domain → | |
| www.hopkinslaw.net | ✓ Let's Encrypt | Let's Encrypt | Aug 12, 2026 | View Certificate Secure this domain → |
| Domain | Certificate | Issuer | Expiry | Actions | |
|---|---|---|---|---|---|
| bluefin-coffee.com Primary | ⊘ Self-Signed | — | — | Secure this domain → | |
| www.bluefin-coffee.com | ⊘ Self-Signed | — | — | Secure this domain → | |
| store.bluefin-coffee.com | ✗ Renewal failed | Sectigo CA Limited | Aug 22, 2026 | View Certificate | |
|
Renewal failed — Account suspended Your account with your certificate provider has been suspended. Your certificate is still active but will not renew until the suspension is lifted. What you can do: Contact your hosting provider immediately to resolve the suspension before your certificate expires. |
|||||
Page size: 20 · 1 2 →
Showing 3 domains · Tick subdomains to select, then click Secure this domain. Or click Secure this domain on any row to secure just that one.
This domain isn't protected by a trusted SSL certificate.
Your Custom ACME credentials are configured. Select subdomains below or click Secure this domain to begin.
| Hostname | Cert Type | Issuer | Expiry | Status | Action | |
|---|---|---|---|---|---|---|
| *.acme-corp.org | — | — | — | Not Secured | Secure this domain → | |
| acme-corp.org | Self-Signed | — | — | Not Secured | Secure this domain → | |
| www.acme-corp.org | Self-Signed | — | — | Not Secured | Secure this domain → | |
| mail.acme-corp.org | Self-Signed | — | — | Not Secured | Secure this domain → | |
| shop.acme-corp.org | Self-Signed | — | — | Not Secured | Secure this domain → | |
| api.acme-corp.org | Self-Signed | — | — | Not Secured | Secure this domain → |
This domain isn't protected by a trusted SSL certificate.
Issue a free Let's Encrypt certificate, purchase a paid certificate, or set up Custom ACME credentials to use your own CA.
| Hostname | Cert Type | Issuer | Expiry | Status | Action | |
|---|---|---|---|---|---|---|
| *.hopkinslaw.net | — | — | — | Not Secured | Secure this domain → | |
| hopkinslaw.net | Self-Signed | — | — | Not Secured | Secure this domain → | |
| www.hopkinslaw.net | Self-Signed | — | — | Not Secured | Secure this domain → |
This domain isn't protected by a trusted SSL certificate.
Issue a free Let's Encrypt certificate, or set up Custom ACME credentials to use your own CA. The cPanel Store is not available for this account.
| Hostname | Cert Type | Issuer | Expiry | Status | Action | |
|---|---|---|---|---|---|---|
| *.bluefin-coffee.com | — | — | — | Not Secured | Secure this domain → | |
| bluefin-coffee.com | Self-Signed | — | — | Not Secured | Secure this domain → | |
| www.bluefin-coffee.com | Self-Signed | — | — | Not Secured | Secure this domain → | |
| store.bluefin-coffee.com | Self-Signed | — | — | Not Secured | Secure this domain → |
← Back to SSL Selection · Upgrading: acme-corp.org
⭐ Why buy from cPanel Store?
Certificate reissued automatically before expiry — no manual action needed.
Certificate installed on your domain automatically after purchase.
Sectigo certificates recognised by 99.9% of browsers.
Verify your company name for stronger customer trust.
Select the certificate that suits your needs:
Comodo DV SSL Certificate
Fast issuance with domain-level verification. Ideal for blogs, personal sites, and small businesses.
- Domain ownership verified
- HTTPS padlock in browser
- Auto-reissue via cPanel Store
- Includes parent domain
Wildcard available — covers all subdomains
Comodo OV SSL Certificate
Your business identity verified — company name appears in the certificate for stronger trust.
- Business identity verified
- Company name in certificate
- Auto-reissue via cPanel Store
- Includes parent domain
Wildcard available — covers all subdomains
Comodo EV SSL Certificate
The highest trust level — recommended for e-commerce, financial services, and checkout pages.
- Strictest validation process
- Maximum browser trust indicators
- Auto-reissue via cPanel Store
- Ideal for checkout pages
🔒 Secure checkout — Pricing displayed at checkout.
Verify domain ownership
Before we can issue your certificate, we need to confirm you control each domain. This usually takes a few seconds.
Set up Custom ACME
About Custom ACME
Custom ACME lets you automate certificates from your own Certificate Authority. You'll need three pieces of information from your hosting provider: Directory URL, EAB Key ID, and EAB HMAC Key. These are stored once and reused for all your certificates. Learn more →
The ACME endpoint URL provided by your CA.
Treat this like a password — it authenticates your account with the CA.
These credentials are saved for your account and reused for all certificates issued via Custom ACME.
Custom ACME — Post-issuance error states
How each post-issuance error appears inline in the SSL/TLS Status tab. Each tab shows a domain row with the error expanded beneath it. Note: "Expiring soon" is not a UI status for Custom ACME — it is handled as an email notification only (see Screen 11 → Expiry warning).
All Custom ACME domains on the account are affected when credentials are invalid.
Domain: shop.acme-corp.org · Issuer: Sectigo CA Limited
Per-cert Manage modal (restructured)
Reissue / Modify Certificate / Unassign as action cards with descriptions and an Execute button each. Advanced Settings includes ACME credentials, Account URL, and per-cert toggles (HTTPS Redirect, HSTS).
Custom ACME — Error state catalogue
Customer-facing error states for Custom ACME certificate failures. Each tab shows the full error structure. Language avoids CA/technical jargon — always directed to the hosting provider.
❌ Certificate request failed — Credentials not accepted
Domain: shop.acme-corp.org
Your certificate provider did not accept the credentials associated with your account. This usually happens when your credentials have expired, been rotated, or were entered incorrectly.
Contact your hosting provider to get a fresh set of credentials and update them in your account settings.
Current state
This domain remains in its previous state (insecure). No certificate has been issued. Any existing certificate on this domain is unaffected.
What you can do
- Contact your hosting provider to obtain updated credentials, then update them in Advanced Settings and retry.
- Choose a different certificate type for this domain (e.g. Let's Encrypt).
- Try again later if you believe this was a temporary issue.
Mandatory notification emails — all 6
Always sent regardless of admin/user notification radio settings. Recipients vary per notification type.
Recipients: Customer + Reseller
Action required: Your credentials were rejected
Hi,
Your certificate provider rejected the credentials configured for acme-corp.org. Until this is resolved, all certificates managed via Custom ACME on your account will not renew.
- Contact your hosting provider to obtain updated credentials.
- Once you have new credentials, update them in your cPanel account at: SSL/TLS Status → Manage → Advanced Settings → Edit ACME Credentials.
Affected account: customer1 on yourhost.example.com
Certificate provider: Sectigo CA Limited
Error timestamp: 14 Jun 2026 13:42 UTC
— Your cPanel hosting team