Automating Let's Encrypt SSL Issuance in cPanel & WHM
Learn how to configure and automate Let's Encrypt SSL issuance using cPanel's AutoSSL and WHM API to eliminate manual certificate renewals.
01 Jan 2026, 17:37 UTC

Solving SSL Expiration with AutoSSL
Manually tracking SSL expiration dates for dozens of domains is a recipe for downtime. The primary challenge in cPanel environments is ensuring that the AutoSSL system—which leverages the ACME (Automated Certificate Management Environment) protocol—is correctly configured to issue and renew certificates without manual intervention.
The takeaway: By configuring the Let's Encrypt provider within WHM, you shift from manual CSR (Certificate Signing Request) generation to an automated lifecycle where the server handles validation and installation automatically.
Prerequisites for Automation
- cPanel/WHM Version: Version 80 or higher (native Let's Encrypt integration).
- Root Access: Administrative access to Web Host Manager (WHM).
- DNS Reachability: The domain must have a valid A record pointing to the server's IP. Let's Encrypt must be able to reach the
.well-known/acme-challenge/directory via HTTP/HTTPS. - Firewall Rules: Port 80 must be open to allow the Let's Encrypt validation servers to verify domain ownership.
Configuring the Let's Encrypt Provider
To move from manual certificates to automated Let's Encrypt issuance, follow these steps in the WHM interface:
- Log into WHM as root.
- Navigate to Manage AutoSSL.
- Under the Providers tab, select Let's Encrypt.
- Check the box to agree to the Let's Encrypt Terms of Service.
- Click Save.
Triggering Immediate Issuance via API
While AutoSSL runs on a schedule, you may need to force a certificate check for a new account immediately. This can be done via the WHM API 1. Run the following command from the server terminal as the root user:
# Force AutoSSL to check and install certificates for all users
whmapi1 run_autossl_check_all_users
Risk: Avoid running this command repeatedly in a short window. Let's Encrypt imposes a rate limit of 5 failed validation attempts per 7 days per domain. Exceeding this can block your domain from receiving certificates for a week.
Verification and Diagnostics
Once the process is triggered, you must verify that the certificate was actually installed and is not a fallback self-signed cert.
Method 1: API Check
Run this command to list the active SSL certificates and their expiration dates:
# List SSL certificates for a specific user
whmapi1 list_ssl_certs user=USERNAME
Method 2: Log Analysis
If a domain fails to secure a certificate, the reason is recorded in the AutoSSL logs. Check the following path for validation errors (such as DNS mismatches or firewall blocks):
tail -f /var/log/letsencrypt/letsencrypt.log
Comparison: HTTP-01 vs. DNS-01 Validation
| Feature | HTTP-01 (Default) | DNS-01 |
|---|---|---|
| Mechanism | Places a file in .well-known/ |
Requires a specific TXT record |
| Wildcards | Not supported | Supported (e.g., *.domain.com) |
| Requirement | Port 80 must be open | API access to DNS provider |
Limitations and Recovery
AutoSSL handles renewals automatically via a system cron job. However, if a renewal fails due to a DNS change, the certificate will expire. To recover a failed state:
- Correct the DNS records or firewall rules blocking port 80.
- Navigate to SSL/TLS Status in WHM.
- Select the affected domain and click Run AutoSSL.
If you previously installed a manual third-party certificate that is now expired, AutoSSL may not overwrite it automatically. You must remove the expired certificate from the Install an SSL Certificate on a Domain menu before AutoSSL can take over management.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.