How to Install an SSL Certificate in cPanel?
· Guide
On shared or VPS hosting accounts running cPanel, there are two main paths to installing an SSL certificate: the free, automatic AutoSSL, or manually installing a certificate you purchased from a provider like PekiSSL. Here's how each works:
1. Free Installation via AutoSSL
Most modern cPanel accounts have AutoSSL enabled by default, automatically issuing and renewing free DV certificates — typically via Let's Encrypt (some hosts use Sectigo). Check the "SSL/TLS Status" page in cPanel; a green padlock next to your domains means AutoSSL is already active. AutoSSL only provides Domain Validation (DV) — if you need organizational identity verification (OV/EV), manual installation is required.
2. Manually Installing a Purchased Certificate
PekiSSL automatically generates the private key and CSR for you at order time — you never have to create anything yourself. Once the certificate is ready, downloading it from your dashboard gives you three files: the certificate (.crt), the private key (.key), and the CA bundle (.ca-bundle). In cPanel, go to "SSL/TLS" > "Install and Manage SSL for your site (HTTPS)", select your domain, and fill in the three fields with the corresponding file contents:
• Certificate (CRT): the certificate file's content
• Private Key (KEY): the private key file's content
• Certificate Authority Bundle (CABUNDLE): the intermediate chain
Click "Install Certificate" and cPanel will validate and activate it.
3. Enforce HTTPS Redirection
Once the certificate is installed, go to the "Domains" section on the cPanel homepage and enable "Force HTTPS Redirect" next to your domain. This automatically 301-redirects all HTTP requests to HTTPS — no separate .htaccess rule needed.
4. Common Errors
- "Incomplete certificate chain" warning: usually caused by leaving the CA Bundle field empty — make sure you paste the full contents of the .ca-bundle file you downloaded from PekiSSL.
- "Certificate does not match this domain" error: the domain entered when generating the CSR doesn't match what the certificate covers — you'll need to reissue for the correct domain.
- AutoSSL overwriting your PekiSSL certificate: on some hosts, AutoSSL periodically scans and overwrites manually installed certificates — if this happens, exclude that domain from AutoSSL via the "Exclude" option on the SSL/TLS Status page.
Visit the PekiSSL product page to find the right certificate for your needs.