Using cPanel AutoSSL to Secure Addon Domains Without Manual Certificates
Learn how cPanel’s AutoSSL automatically provisions and renews Let’s Encrypt certificates for addon domains, with steps to enable, verify, and manage its limitations.
30 Jul 2025, 04:11 UTC

Problem: Managing SSL for Multiple Addon Domains
When you host several addon domains or subdomains in a single cPanel account, obtaining and renewing SSL/TLS certificates for each name can become a repetitive manual task. Missing a renewal leads to browser warnings and potential loss of trust.
How AutoSSL Works in cPanel
cPanel’s AutoSSL feature runs a background cron job that, for every domain owned by a user, checks that the domain’s DNS A record resolves to the server’s IP address. If the check passes, AutoSSL initiates an HTTP‑01 challenge with Let’s Encrypt (or Comodo, depending on the provider configured in WHM). Upon successful validation, the certificate is fetched, installed into the appropriate Apache virtual host, and linked to the domain’s SSL/TLS entry. The cron repeats roughly every twelve hours, automatically renewing certificates when they are within thirty days of expiry.
Enabling AutoSSL for an Addon Domain
- Log in to cPanel with the account that owns the addon domain.
- Navigate to Security → SSL/TLS Manager → Manage AutoSSL.
- In the Manage Users tab, locate the cPanel user and toggle the
AutoSSLswitch to On. This enables the feature for all domains under that user. - Optionally, click the Manage Domains tab to enable or disable AutoSSL for individual domains (e.g., turn it off for a parked domain that uses an external CDN).
- Save the changes. cPanel will schedule the next AutoSSL run; you can trigger it immediately by clicking the Run AutoSSL button on the same page.
Worked Example: Securing a New Addon Domain
Suppose you have added the addon domain shop.example.com and created an A record that points to your server’s IP address.
- After enabling AutoSSL for the user (as described above), wait for the cron to run or press Run AutoSSL.
- cPanel will log the HTTP‑01 challenge attempt. You can view the log in WHM at
Home → Plugins → AutoSSL Logor, if you have SSH access, run:
# Requires root or a user with sudo access to read the AutoSSL log
sudo tail -f /var/log/autossl.log
Look for lines similar to:
[INFO] AutoSSL: Starting request for shop.example.com
[INFO] AutoSSL: HTTP-01 challenge token received
[INFO] AutoSSL: Challenge validation succeeded
[INFO] AutoSSL: Certificate installed for shop.example.com
Once the run finishes, visit https://shop.example.com in a browser. The lock icon should indicate a valid certificate, and the certificate details will show Let’s Encrypt Authority X3 (or the current intermediate) as the issuer.
To confirm that automatic renewal is active, check the AutoSSL page again; the Next Renewal column will show a date roughly sixty days in the future. You can also force a renewal test by clicking the Renew AutoSSL button.
Trade‑offs and Limitations
- DNS requirement: AutoSSL only works when the domain’s A record points directly to the cPanel server. If the domain is behind a CDN, WAF, or proxy that terminates SSL elsewhere, the HTTP‑01 challenge will fail because the validation token cannot be reached.
- Rate limits: Let’s Encrypt enforces a limit of 50 certificates per registered domain per week. Creating many subdomains or frequently re‑issuing certificates (e.g., during automated testing) can hit this threshold, causing AutoSSL to pause until the limit resets.
- No wildcard support: The free Let’s Encrypt provider in AutoSSL issues only single‑domain certificates. To secure a wildcard like
*.example.comyou must either purchase a commercial provider configured in WHM or generate a manual CSR and install the certificate outside of AutoSSL.
Actionable Checklist
- Verify that each domain’s DNS A record resolves to your server’s IP (
dig +short shop.example.comshould return the expected address). - Enable AutoSSL for the relevant cPanel user via SSL/TLS Manager → Manage AutoSSL.
- Trigger an immediate run with the Run AutoSSL button and monitor the AutoSSL log for success messages.
- Confirm the certificate in the browser and note the issuer.
- Check the Next Renewal date; set a calendar reminder to review the AutoSSL log monthly for any error entries.
- If you encounter validation failures, temporarily disable any proxy or CDN for the validation period, or switch to DNS‑01 validation via a paid provider that supports it.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.