Automating Let’s Encrypt SSL in cPanel with AutoSSL: Setup, Example, and Caveats
cPanel’s AutoSSL automatically requests and renews Let’s Encrypt certificates for all domains on the server. Learn how to enable it, run a practical example, and understand its limits and trade‑offs.
23 Apr 2026, 13:14 UTC

Problem: Manual SSL Management is Tedious and Error‑Prone
Every time a new domain or sub‑domain is added to a cPanel account, the administrator must:
- Obtain a certificate from a CA (often Let’s Encrypt).
- Upload the certificate files (CRT, KEY, CA bundle) into cPanel’s SSL/TLS Manager.
- Schedule renewals to avoid service interruption.
With dozens or hundreds of domains, this process scales poorly and increases the risk of expired certificates.
Thesis: AutoSSL Turns SSL Management into a Background Job
cPanel’s AutoSSL feature automatically requests and renews Let’s Encrypt certificates for every domain it manages. It runs as a daemon in WHM, checks domains nightly, and uses HTTP‑01 validation to prove ownership. The result? Zero manual steps, consistent encryption, and automatic renewal.
What AutoSSL Actually Does
AutoSSL operates in three distinct stages:
- Discovery – The daemon scans all accounts for domains that lack a valid certificate or have an expiring one.
- Request – For each domain, it contacts the chosen CA (Let’s Encrypt by default) and requests a new certificate.
- Validation & Deployment – The CA performs an HTTP‑01 challenge. AutoSSL creates a temporary file in the domain’s document root (e.g.,
/.well-known/acme-challenge/…) that the CA can fetch. Once validated, the certificate is imported into cPanel’s SSL/TLS Manager.
Because the process is fully automated, you only need to enable it once and let the system handle renewals until the certificate’s 90‑day validity expires.
Enabling AutoSSL: Global vs Per‑User
Admins can enable AutoSSL in two scopes:
- Global – Applies to every account on the server.
- Per‑User – Specific accounts can opt in or out.
To enable globally:
# In WHM, go to "Manage AutoSSL" → "Select a provider"
# Choose "Let’s Encrypt" (or the cPanel‑managed Comodo provider).
# Tick "Enable AutoSSL for all accounts" and click Save.
To enable for a single account:
# In WHM, navigate to "Manage AutoSSL" → "Select a provider"
# Select the account from the list, tick "Enable AutoSSL", and save.
Both actions create a configuration file at /usr/local/cpanel/etc/autossl.conf that the daemon reads.
Worked Example: Enabling AutoSSL for example.com
Assume example.com is a new domain in account alice. Follow these steps:
- Verify DNS & Port 80 – Ensure
example.comresolves to the server’s IP and that TCP port 80 is open to the public.- Command:
dig +short example.comshould return the server IP. - Command:
nc -zv example.com 80should succeed.
- Command:
- Enable AutoSSL for the account – In WHM, go to Manage AutoSSL, select the
aliceaccount, tick Enable AutoSSL, and click Save. - Run a manual check – Trigger the daemon to process the new domain immediately.
# Run from the command line as root /usr/local/cpanel/bin/autossl_check --account alice - Verify the certificate – After the check completes, log into cPanel for
alice, open SSL/TLS Manager, and confirm thatexample.comshows a certificate issued by Let’s Encrypt with a 90‑day validity. - Check the log – The output of
autossl_checkwill contain a line such asexample.com: Success. If it showsFailure, review the error message (often DNS or firewall related).
Trade‑offs and Limitations
- Rate Limits – Let’s Encrypt imposes 50 certificates per registered domain per week. If you add many sub‑domains in a short time, AutoSSL may hit this limit and fail to issue certificates. The daemon logs the error; you can retry later.
- HTTP Validation Dependency – AutoSSL requires that
http://example.com/.well-known/acme-challenge/…be reachable. If your firewall blocks port 80 or if you use a CDN that terminates HTTP before reaching the server, validation will fail. - Domain Ownership – AutoSSL will not issue a certificate if the domain does not resolve to the server’s IP. Double‑check DNS propagation before enabling.
- Limited Customization – AutoSSL cannot be configured to use alternative validation methods (e.g., DNS‑01) or to request certificates with custom SANs beyond the domain itself.
Practical Check: Confirming AutoSSL is Working
- Navigate to
https://yourdomain.comand inspect the certificate in your browser. It should list Let’s Encrypt as the issuer and show a 90‑day expiry. - In WHM, run
/usr/local/cpanel/bin/autossl_check --alland look forSuccessentries. - Review the AutoSSL log at
/usr/local/cpanel/logs/autossl.logfor any failures.
Actionable Closing: Keep AutoSSL Running Smoothly
1. Enable AutoSSL globally if you control multiple accounts and want consistent encryption.
2. Monitor logs monthly for failures; address DNS or firewall issues promptly.
3. Consider a secondary provider (cPanel’s own Comodo) if you hit Let’s Encrypt rate limits frequently.
4. Document the process for your team so new domain additions automatically benefit from encrypted HTTPS.
By turning SSL management into a background job, AutoSSL frees administrators to focus on higher‑value tasks while keeping every user’s traffic secure.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.