How to Install an SSL Certificate in Plesk?
· Guide
Plesk offers a more visual interface for SSL installation than most other control panels. There are two main paths: free automatic installation via the built-in Let's Encrypt extension, or manually uploading a certificate you purchased from PekiSSL.
1. Free Installation via Let's Encrypt
Most Plesk versions come with the "Let's Encrypt" extension pre-installed. On the Websites & Domains page, click the "Let's Encrypt" icon next to your domain, select which domains/subdomains to cover (including www), and click "Get it free." The certificate installs within seconds, and Plesk handles automatic renewal on its own.
2. Manually Installing a Purchased Certificate
Using the certificate files downloaded from your PekiSSL dashboard, go to Websites & Domains > SSL/TLS Certificates. Click "Add SSL/TLS Certificate" and:
• Enter a certificate name (for identification within Plesk only)
• Use "Upload certificate files" to upload the certificate (.crt), private key (.key), and CA bundle (.ca-bundle) separately, or paste their contents into the corresponding fields
3. Assign the Certificate to Your Domain
Uploading alone isn't enough — you need to bind the certificate to your domain. Go to Websites & Domains > Hosting Settings, check the "SSL/TLS support" box, and select the certificate you just uploaded from the dropdown. Click "OK" to save.
4. Enable HTTPS Redirection
On the same Hosting Settings page, check "Permanent SEO-safe 301 redirect from HTTP to HTTPS" to automatically redirect all HTTP traffic — no separate .htaccess rule needed.
5. Common Issues
- Newly uploaded certificate doesn't appear in the dropdown: refresh the page, as some Plesk versions don't update the list immediately.
- Errors on the www vs non-www version: make sure the certificate's SAN field covers both www.domain.com and domain.com — specify this when ordering from PekiSSL.
- Let's Encrypt renewal fails: this usually means the domain's DNS record no longer points to the server — Let's Encrypt validation requires the domain to actually resolve to that server.
Visit the PekiSSL product page to find the right certificate for your needs.