cPanel, Run AutoSSL Manually
Occasionally AutoSSL fails to run automatically and an SSL certificate expires. You can run AutoSSL manually using the SSL/TLS Certificates feature from your cPanel dashboard.
The cPanel SSL/TLS interface was recently updated. The previous SSL/TLS, SSL/TLS Status, and SSL/TLS Wizard interfaces are now combined into the SSL/TLS Certificates page.
Symptoms of an expired SSL certificate
- Visitors to your site see a warning message when they visit https://accountname.web.illinois.edu
- Visitors to your site see a warning message when they visit http://accountname.web.illinois.edu if you have Force HTTPS Redirect enabled
- Visitors to your site see a warning message when they visit https://yourcustomdomain.illinois.edu
- Visitors to your site see a warning message when they visit http://yourcustomdomain.illinois.edu if you have Force HTTPS Redirect enabled
Solution
- Visit https://web.illinois.edu
- Click Illinois Login
- Follow the login process to access your cPanel account list
- Click on the account that is exhibiting this issue
- Click SSL/TLS Certificates
- Select the Wizard tab. Under the Wizard tab, select the checkbox next to the domain(s) needed. cPanel will perform a Domain Control Validation check to verify that the domain can be secured.
- This check confirms that you control the domain. A colored dot shows the result:
- Gray — DCV check not yet complete.
- Green — DCV check passed.
- Red — DCV check failed.
- Confirm that the correct domain(s) appears under ‘Selected Domains’, then click Continue.
- Note: Your primary domains must have a valid certificate. You can ignore certificate errors for domains that are not actively in use, such as mail.customdomain.illinois.edu

- Under ‘Select the product that you would like for this certificate’, click ‘Let's Encrypt Certificate’.

- A Let's Encrypt Certificate window will appear. Review the information and acknowledge the Let's Encrypt Terms of Service, then click Continue

10. cPanel will begin issuing and installing the certificate. The domain will temporarily display “Adding certificate…” in a pop up graphic display while the process is underway.
- Wait for the process to be completed. A confirmation message will appear in the upper-right corner of the page, and the domain’s status will update when the certificate has been successfully installed.

- Review the certificate status and any error messages that were received
Note
If your certificate is not yet expired, AutoSSL uses the following criteria to determine whether a new certificate will be issued:
- If the existing certificate is self-signed or if there is no certificate installed, AutoSSL will attempt to request and install a new certificate.
- If a certificate that was previously issued by AutoSSL will expire within 10 days, AutoSSL will attempt to request and install a new certificate.
- If a certificate from a different provider is currently installed, AutoSSL will only attempt to replace it when it is within 3 days of expiration.
If AutoSSL requests a new certificate, there can be a delay between that request and successful installation of the certificate.
It is also possible that AutoSSL will fail to request or install a new certificate for a variety of reasons. Handling the possibility of failures is built into the process for AutoSSL renewals, and in most cases the next attempt to renew the certificate will succeed.
If you are within a couple of days of expiration and still unable to get a new certificate to install through AutoSSL, the Web Hosting team can check the system logs for any unusual blockers that can be cleared to allow the certificate issuance to succeed. You can open a ticket with the team at https://go.illinois.edu/cpanelhelp.