4 Mistakes People Make When Getting a Free SSL Certificate

· Guide

Getting a free SSL certificate now takes a few minutes. The certificate is issued, installed on the server, and the padlock appears in the address bar. Then someone opens your site with www and the browser shows a red warning.

The problem usually isn't the certificate itself, but what it covers. In this article we go through the four most common mistakes people make when getting a free SSL certificate, and how to avoid each one. The second one comes from a real situation a PekiSSL.com customer ran into this week.

1. Forgetting www

A certificate issued for example.com covers only example.com. To the browser, www.example.com is a separate address. If it isn't listed on the certificate, visitors see a "Your connection is not private" warning.

This mistake is sneaky, because you always open your site the same way and everything looks fine. The visitor who sees the warning is the one who arrives through another link, or types www out of habit.

How to avoid it: Make sure the certificate covers both example.com and www.example.com. With free certificates, the easiest way is the "wildcard + main domain" certificate described below.

On PekiSSL.com: For a free single-domain order, the checkout screen states clearly which address the certificate covers and which it doesn't, and suggests Free Wildcard SSL for both addresses.

2. Typing "www." into the Wildcard Field

A wildcard certificate in the form *.example.com covers all subdomains of a domain: www.example.com, mail.example.com, shop.example.com...

This week a customer typed www.example.com into the field while ordering a wildcard certificate. The certificate was issued for *.www.example.com. That covers addresses below www, such as x.www.example.com, which practically nobody uses. The main domain and other subdomains like mail.example.com were left out.

The rule is simple: the asterisk in a wildcard stands for exactly one level. *.example.com already covers www.example.com. Adding www. in front doesn't widen the coverage; it moves it to the wrong place.

How to avoid it: When ordering a wildcard, type the bare domain: example.com. The system adds the asterisk and the dot.

On PekiSSL.com: After this case, we added a warning to checkout. If an address starting with www. is typed into the wildcard field, the screen says "No need to type www." and offers a one-click fix to *.example.com. Our customer got the correct certificate the same day.

3. Assuming the Wildcard Also Covers the Main Domain

This one is the reverse of the second mistake and at least as common. *.example.com covers www.example.com, but not example.com itself. The asterisk means "something", and on the main domain there is nothing in its place.

The result: even with a wildcard certificate, you may still see a warning when your site is opened as example.com.

How to avoid it: Get the certificate so that it covers *.example.com and example.com together. One certificate then protects the main domain, www and every other subdomain. This also solves the www problem from mistake 1.

On PekiSSL.com: In a Free Wildcard SSL order, the "Include apex domain" option is checked by default. The screen lists exactly which addresses the certificate will protect before you place the order. Both addresses are validated by a single CNAME record; no separate DNS record is needed.

4. Forgetting the 90 Days

Almost all free certificates are valid for 90 days. Installing one and forgetting about it means that three months later your site opens one morning with a "Not secure" warning. This is often noticed through a customer complaint or a drop in sales.

Some server tools renew automatically. But if you got the certificate from a panel and installed it manually, renewal is up to you as well.

How to avoid it: Put the certificate's expiry date in your calendar and get and install a new one before it expires. Paid certificates offer long subscriptions, but with a free certificate, tracking is on you.

On PekiSSL.com: Free certificates are not renewed automatically, and we say so clearly. Instead, we send email reminders 30, 15 and 7 days before expiry. To renew, simply place a new free order for the same domain. As long as the CNAME record you added earlier is still in place, you don't need to touch your DNS.

Quick Checklist

After installing your free SSL certificate, check the following:

If you see the padlock everywhere and the expiry date is noted, you're done.

You can get your free SSL certificate at PekiSSL.com. All you need is one CNAME record at your DNS provider. Choose Free Wildcard SSL to protect your main domain and www together.

All blog posts