The free SSL certificate did not renew: why AutoSSL fails and what to check

The short answer: the free certificate that comes with the account (AutoSSL, from Let’s Encrypt) is issued and renewed by itself, but only if the server can prove the domain is yours and points here. When it fails, it is nearly always one of five things: the domain points elsewhere, a CAA record blocks issuance, a rule on the site blocks the check, the name is new, or something is stuck with the account.

1. See the certificate’s status

In cPanel, open “SSL/TLS Status”. It shows every domain and subdomain on the account with its status and expiry date. A domain without a padlock, or due for renewal, is the one that matters. From there you can launch a new AutoSSL run with the button provided.

2. The five causes, in order

Cause How to recognise it What to do
The domain does not point to this server The nameservers, seen in WHOIS, are not your account’s, or there is an A record to another address. Fix the pointing and wait. See no padlock: the causes, in order.
A CAA record blocks issuance The domain has a CAA that does not authorise the authority AutoSSL uses. Fix or remove the record: CAA records.
A rule on the site blocks the check A redirect or an .htaccess rule that blocks the /.well-known/ path, a protection asking for a password at the site root, or a maintenance plugin that answers everything. Exclude that path from the rule. See the redirect to HTTPS.
The name is new or outside the certificate A subdomain created a short while ago, or the www the certificate does not include. Wait for the next AutoSSL run or launch it by hand.
Behind a protection service With Cloudflare in a strict mode, the check may not reach the server. See switching on SSL at Cloudflare without breaking the site.

3. After fixing it

1 Launch AutoSSL again in “SSL/TLS Status” and give it a few minutes.
2 Reload the status and see whether the domain now shows the new expiry. Open the site in a private tab: the browser caches certificates and pages.
3 If it still fails, cPanel shows the reason, in English, next to the domain. Copy the sentence as it is and send it in a support ticket with the domain. It tells us straight away which check did not pass.
If the certificate has already expired, visitors see a security warning blocking the site. Do not tell them to “continue anyway”: that teaches them to ignore warnings, which is exactly what attackers want. Fix it and, meanwhile, warn them through another channel.
Have a paid certificate and AutoSSL at the same time? The paid one may be the one that has expired. See which is in use in “SSL/TLS Status” before looking for the problem in the wrong place. For what each type covers, see DV, OV and EV certificates.

Still no certificate after all this? Send us the domain and the cPanel message.

Open a support ticket

SEE ALSO

No padlock on your site: the causes, in order

CAA records: who may issue certificates for your domain

DV, OV and EV certificates

Why does my SSL certificate show fewer than 365 days?

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?