How to Install an SSL Certificate
WordPress & Managed Editor
Disclosure: Some links on this page are affiliate links — if you sign up through one, we may earn a commission at no extra cost to you. It never changes our ratings, rankings or verdicts: we don't sell hosting and take no pay-for-placement.
Who it's for
- First-time site owners
- Small business owners
- Anyone launching a new domain
What Installing an SSL Certificate Involves
An SSL/TLS certificate encrypts the connection between a visitor’s browser and the server, and is what enables the padlock icon and https:// in the address bar. Installing one means either issuing a free certificate automatically through the hosting panel, the standard route on nearly every host today, or, less commonly, generating a Certificate Signing Request (CSR) for a purchased certificate and installing the issued files manually. See SSL certificates in hosting for how certificate types differ, and SSL, TLS & HTTPS explained for how the underlying terms relate to one another.
Prerequisites Before Installing SSL
- A domain already pointed at the hosting account, since certificate issuance verifies domain ownership through DNS or a file check.
- Panel access — cPanel, Plesk, or the host’s SSL/security section.
- A purchased certificate’s files, if not using a free automated certificate — typically a
.crtfile and a private key.
How to Install SSL: Step-by-Step
Issue a Free Let’s Encrypt Certificate or Generate a CSR
- Log in to the hosting panel and open the SSL/TLS or Security section.
- Check for an “AutoSSL” or “Let’s Encrypt” option. Most hosts offer this as a one-click free certificate covering the domain and its
wwwsubdomain. - Run the automated issuance, if available, and wait a few minutes for the certificate to be generated and installed.
- For a manually purchased certificate, generate a CSR first (the panel’s SSL section has a CSR generator), submit it to the certificate authority, then upload the returned certificate files into the same panel section.
Force HTTPS Redirects and Update Site Settings
- Force HTTPS redirects. Once the certificate is active, set up a redirect from
http://tohttps://, either via the panel’s “Force HTTPS” toggle or a redirect rule, so visitors and search engines land on the secure version by default. - Update the site’s internal settings (e.g. WordPress’s Site Address/WordPress Address under Settings → General) to use
https://if they were previously set tohttp://.
Verifying SSL Is Working
Load the live domain in a browser and confirm the padlock icon appears with no warning. Click the padlock to check the certificate details — issuer, domain match, and expiry date. Run the site through a free SSL checker tool to catch anything the browser doesn’t surface directly, such as an incomplete certificate chain. Finally, check a few different pages, not just the homepage, since mixed content issues sometimes affect only specific templates.
Common Errors When Installing SSL
- “Not secure” warning even after installing a certificate — usually mixed content, where some images, scripts, or stylesheets still load over plain
http://. - Certificate installed but doesn’t cover a subdomain — the automated issuance may have only covered the root domain; reissue with the subdomain explicitly included.
- “Your connection is not private” error — the certificate may not have finished propagating, or the domain’s DNS doesn’t match what was verified during issuance.
- Auto-renewal fails silently — free automated certificates typically renew every 60–90 days; if DNS or panel settings changed in between, renewal can fail and needs to be re-triggered manually.
- SSL works on the main domain but not a fresh subdomain — see how to create a subdomain for the DNS step that needs to exist first.
Why SSL Also Affects More Than Security
Beyond encryption and the padlock, an active certificate is factored into how browsers and search engines treat a site. It’s a baseline requirement for hosting security more broadly — an unencrypted site is flagged as a risk regardless of how well everything else is configured. It’s also a prerequisite for accepting any kind of form submission, login, or payment on a site without triggering a browser warning.
FAQ
Is a free SSL certificate as secure as a paid one? Yes, for encryption purposes — a free Let’s Encrypt certificate provides the same level of encryption as a paid one. Paid certificates mainly add extended validation branding or warranty coverage, not stronger encryption.
How often does an SSL certificate need to be renewed? Free automated certificates typically renew every 60–90 days automatically. Manually purchased certificates are usually issued for one year and need to be reinstalled at renewal.
Can I install SSL myself without contacting my host? On almost every modern host, yes — the automated free-certificate option in the panel requires no support ticket. Manual installation of a purchased certificate is slightly more involved but still self-service on most panels.
What happens if I don’t install SSL at all? Browsers mark the site “Not Secure,” visitors see a warning before submitting any form, and the site is disadvantaged for ranking purposes compared to sites that are properly secured.