Free SSL certificates and how HTTPS works on your account

Every website should be served over HTTPS. Browsers mark sites without it as "Not secure", and search engines treat it as a ranking signal. A certificate is what makes HTTPS possible.

You do not necessarily have to buy one.

Free certificates

Every account includes free certificates, issued automatically. Once your domain points at our server, a certificate is requested, installed and renewed for you. There is nothing to install and nothing to renew — and nothing to buy.

Allow a few hours after the domain starts resolving to us. Issuance is not instant, because the certificate authority has to verify the domain reaches our server first.

A free certificate encrypts traffic exactly as well as a paid one. The padlock is identical and the encryption is identical.

When you should buy one instead

Paid certificates are worth it in specific cases, not as a general upgrade:

  • Organisation or Extended Validation — the issuer verifies your company's identity, not just control of the domain. Some sectors and some customers expect it.
  • A warranty — paid certificates carry financial backing that free ones do not.
  • Wildcards, if you need one certificate covering many subdomains and automatic issuance is not covering them.

If you need one of those, see our article on purchasing and installing your own certificate, or open a ticket and we will handle it.

Making the site actually use HTTPS

Having a certificate is not the same as using it. After it is issued:

  1. Force HTTPS. In cPanel, open Domains and switch on Force HTTPS Redirect for your domain. Visitors arriving over http:// are then sent to the secure version automatically.
  2. Update your site's own address. In WordPress this is Settings > General: both the WordPress Address and Site Address should start https://.
  3. Fix mixed content. If any image, script or stylesheet is still loaded over http://, the browser will not show a full padlock. The browser console lists exactly which resources are at fault.

"Not secure" even though the certificate is installed

Almost always mixed content — step three above. Open the page, press F12, and look at the console for warnings naming an http:// resource. Those are usually hardcoded image URLs in old posts or a theme setting.

The certificate did not issue

Automatic issuance requires the domain to resolve to our server, because that is how the certificate authority proves you control it. It will not issue while the domain still points at your previous host. Common causes:

  • Nameservers not yet changed, or still propagating.
  • An A record pointing somewhere else, overriding the nameservers.
  • A CAA record on the domain restricting which authorities may issue.
  • A subdomain in the request that does not resolve — one failing name can hold up the whole certificate.

If the domain resolves to us and there is still no certificate after 24 hours, open a ticket with the domain name and we will look at the issuance log.

  • 0 Bu dökümanı faydalı bulan kullanıcılar:
Bu cevap yeterince yardımcı oldu mu?

İlgili diğer dökümanlar

Renew Your SSL Certificate

Renewing Your SSL CertificateArticle Purpose:?This article provides step-by-step instructions for...

Powered by WHMCompleteSolution