How to Use the SSL/TLS Wizard in cPanel Print

  • ssl, tls, certificate, cpanel, security, https, encryption, wizard
  • 0

The SSL/TLS Wizard in cPanel simplifies the process of purchasing and installing SSL certificates for your domains. This tool automatically determines the best certificate arrangement for your selected domains and helps you secure your websites with just a few clicks. You can use it to purchase new certificates, monitor pending installations, and manage SSL protection across all domains in your hosting account.

What is the SSL/TLS Wizard?

The SSL/TLS Wizard is a cPanel interface that streamlines SSL certificate management. It displays all domains on your account in a single list and allows you to select which domains need SSL protection. The wizard then automatically calculates the necessary number and type of certificates required to secure your selected domains.

The tool also tracks certificates you've purchased that are awaiting delivery from the certificate provider. This makes it easy to monitor the status of pending SSL installations without checking multiple locations.

Important: The SSL/TLS Wizard only appears in your cPanel account if your hosting provider has enabled the cPanel Store provider in their server configuration. If you don't see this option, contact OBHost support for assistance.

Understanding SSL Certificate Types

The SSL/TLS Wizard supports three main types of SSL certificates, each with different validation requirements and processing times:

Domain Validated (DV) Certificates: These are the quickest to issue, typically available within 24 hours. They only verify that you control the domain name. While issued instantly by the certificate provider, the validation process may take up to 24 hours before installation is possible.

Organization Validated (OV) Certificates: These require verification of your business information and take between 3 and 30 days to process. The certificate issuer validates details about your organization before issuing the certificate.

Extended Validation (EV) Certificates: These offer the highest level of trust and require the most stringent validation. Processing takes between 3 and 30 days due to extensive business verification requirements. These certificates display your company name in the browser address bar.

Requirements Before Purchasing

Before you can purchase SSL certificates through the wizard, certain requirements must be met:

  • You need a cPanelID account, which serves as your username and password for the cPanel Store and related services
  • Your domains must resolve to an IP address on your server (you cannot purchase certificates for domains that don't point to your hosting)
  • The domain must pass a Domain Control Validation (DCV) check to verify ownership

How to Purchase SSL Certificates Using the Default Interface

The default interface is the recommended method for purchasing certificates, especially if you need wildcard certificates that cover multiple subdomains.

Step 1: Select Your Domains

In the SSL/TLS Wizard, you'll see a list of all domains on your account. Select the checkbox next to each domain you want to secure with an SSL certificate.

The interface uses color coding to show each domain's validation status:

  • Gray domains: Have not yet passed the DCV check
  • Green domains: Successfully passed the DCV check and are ready for certificate purchase
  • Red domains: Failed the DCV check and cannot receive a certificate until the issue is resolved

If a domain already has an SSL certificate, you'll see a lock icon and a message indicating that the domain is currently secured. For domains with pending certificates, a "View" link allows you to check the status.

Step 2: Understanding Wildcard Certificates

Domains that begin with an asterisk (*) in the list represent wildcard certificate options. When you select a wildcard certificate, the interface automatically selects all subdomains that the wildcard will protect. This is cost-effective if you have multiple subdomains under a single domain.

Certificates purchased through the cPanel Store automatically include the corresponding www. subdomain for each domain at no additional cost, provided the www. subdomain passes the DCV check.

Step 3: Complete the Purchase

After selecting your domains and confirming they've passed validation, follow the on-screen prompts to complete your purchase. The wizard will guide you through payment and any additional information required by the certificate provider.

The Validation Process Explained

After purchasing a certificate, you'll need to complete the validation process. The certificate issuer (typically Sectigo for certificates purchased through the cPanel Store) will send you an email with validation instructions.

Critical timing: Complete these validation instructions as soon as possible to avoid delays in certificate issuance. Any delay in responding to validation emails can significantly extend the time before your certificate becomes active.

For OV and EV certificates, you may need to provide business documentation, phone verification, or other proof of your organization's legitimacy. The certificate provider may also check publicly available business records.

Monitoring Pending Certificates

The SSL/TLS Wizard displays any certificates that have been purchased but not yet delivered by the certificate provider. You can check the status of these pending certificates and see if any additional action is required on your part.

If a certificate has been pending for longer than expected based on its type (24 hours for DV, up to 30 days for OV/EV), check your email for validation requests you may have missed. You can also click any information messages associated with the certificate to expedite the validation process.

Troubleshooting Common Issues

If a domain fails the DCV check (shows in red), common causes include:

  • DNS records not pointing to your server
  • Domain recently transferred or DNS recently changed (allow 24-48 hours for propagation)
  • Firewall or security settings blocking validation attempts
  • Domain configured incorrectly in your hosting account

If you cannot purchase a certificate for a domain due to a pending certificate, you'll need to wait for the pending certificate to be issued or cancelled before purchasing a new one.

Frequently Asked Questions

Why don't I see the SSL/TLS Wizard in my cPanel account?

The SSL/TLS Wizard only appears if your hosting provider has enabled the cPanel Store provider in their server configuration. OBHost customers should have this feature available by default. If you don't see it, contact our support team at support@obhost.org to enable it for your account.

Can I purchase SSL certificates for domains that don't point to my server?

No, you can only purchase certificates through the SSL/TLS Wizard for domains that resolve to an IP address on your server. This is because the validation process requires proving control of the domain through server-based verification methods. If you need to move a domain to your hosting before purchasing an SSL certificate, update your DNS settings first and wait 24-48 hours for propagation.

How long does it take to receive my SSL certificate after purchase?

The timeline depends on the certificate type. Domain Validated (DV) certificates are typically available within 24 hours after you complete the validation steps. Organization Validated (OV) and Extended Validation (EV) certificates require 3 to 30 days for the certificate provider to verify your business information. Check your email regularly for validation requests to avoid delays.

What happens if I select a wildcard certificate?

When you select a wildcard certificate (shown with an asterisk), the SSL/TLS Wizard automatically selects all eligible subdomains under that domain. This provides a cost-effective way to secure multiple subdomains with a single certificate. The wildcard certificate will protect the main domain and all first-level subdomains, such as blog.example.com, shop.example.com, and mail.example.com.

For assistance with SSL certificate purchases or installation, the OBHost support team is available 24/7. Contact us through our contact page or email support@obhost.org for immediate help with your SSL needs.


Was this answer helpful?

« Back