An expired SSL certificate triggers a browser warning that scares visitors away. Most free certificates renew automatically, but it is worth knowing how to check status and renew manually if needed.
Check Your Expiry Date
- Log in to cPanel.
- Open SSL/TLS Status under Security.
- Review the expiry date next to each domain.
- Look for any certificate marked as expiring soon.
You can also click the padlock in your browser and view the certificate details to see the valid-until date.
Renew a Free AutoSSL Certificate
Let's Encrypt certificates renew automatically, but you can force a renewal:
- In SSL/TLS Status, tick the affected domain.
- Click Run AutoSSL.
- Wait a few minutes and refresh to confirm the new expiry date.
If automatic renewal failed, the cause is almost always a DNS or validation issue.
Renew a Paid Certificate
For purchased certificates, the steps differ:
| Step | Action | | --- | --- | | 1 | Generate a new CSR if required | | 2 | Buy or renew through your provider | | 3 | Receive the new certificate files | | 4 | Install via Manage SSL sites in cPanel |
Avoid Future Lapses
- Leave AutoSSL enabled so free certificates renew on their own.
- Confirm your domain's DNS points to the correct server.
- Watch for expiry reminder emails from your provider.
If AutoSSL keeps failing to renew, a stale redirect or misconfigured DNS record usually blocks validation. Fix that and the certificate will renew on the next run. For help, contact support on WhatsApp at +254 796 358081.