Secure Socket Layer (SSL) certificates are essential for ensuring secure communication between your website and its visitors. By encrypting data transmitted over the internet, SSL certificates help protect sensitive information from being intercepted by malicious actors. When a website is secured with SSL, visitors see a padlock symbol in their browser's address bar, indicating a secure HTTPS connection. This not only builds trust with your users but also positively impacts your search engine rankings, as SSL is a known SEO factor.

Free AutoSSL with Let's Encrypt

GHost Cloud offers free SSL certificates through AutoSSL with Let's Encrypt. This service automatically provisions SSL certificates for your domains once DNS propagation is complete. AutoSSL renews these certificates every 90 days, ensuring continuous protection without manual intervention. You can check the status of your SSL certificates by navigating to the SSL/TLS Status section in your cPanel dashboard.

To get started with AutoSSL, first ensure that your domain's DNS settings are properly configured to point to GHost Cloud's servers. This is crucial because AutoSSL can only issue certificates for domains that have been fully propagated, which can take up to 48 hours. Once DNS propagation is confirmed, AutoSSL will automatically generate and install an SSL certificate for your domain. You do not need to manually renew these certificates, as AutoSSL handles renewals automatically. However, it is advisable to periodically check the SSL/TLS Status in your cPanel to confirm that everything is functioning as expected. If you encounter any issues, such as AutoSSL not issuing a certificate, verify that your DNS settings are correct and that your domain is active.

Ensure that your domain's DNS has propagated completely before AutoSSL can issue a certificate. DNS propagation can take up to 48 hours.

Install a purchased SSL certificate

If you have purchased an SSL certificate, the installation process involves several steps. First, generate a Certificate Signing Request (CSR) in your cPanel by going to the SSL/TLS section and selecting 'Generate, view, upload, or delete SSL certificates'. Submit the CSR to your SSL provider to obtain your certificate files. Once received, return to cPanel, navigate to 'Manage SSL sites' under SSL/TLS, and install the certificate. Be sure to include the Certificate Authority (CA) bundle if provided by your SSL provider.

To generate a CSR, you will need to provide some information about your organisation, such as the domain name, company name, and location. This information will be included in the certificate and must be accurate. After generating the CSR, submit it to your SSL provider, who will issue the certificate files, including the primary certificate, any intermediate certificates, and the CA bundle. When installing the certificate in cPanel, ensure that you paste all the provided certificate files into the appropriate fields. The CA bundle is particularly important as it helps establish a chain of trust from your certificate back to a trusted root certificate authority. After installation, verify the certificate by accessing your site via HTTPS and looking for the padlock icon in the browser's address bar.

Verify your installation

After installing your SSL certificate, verify its proper installation by visiting your website using HTTPS. You can also use online tools like SSL Labs' SSL Test to check your site's SSL configuration. Aim for an A+ rating to ensure your certificate is correctly installed and your site is secure.

Begin by typing your website's URL into a browser, ensuring that you use the HTTPS prefix. If the SSL certificate is correctly installed, you should see a padlock icon in the address bar, indicating a secure connection. For a more detailed analysis, use SSL Labs' SSL Test. This tool provides an in-depth report on your site's SSL configuration, highlighting any potential issues such as weak ciphers or incomplete certificate chains. Achieving an A+ rating means that your SSL setup is robust and secure. If the test reveals any issues, follow the provided recommendations to improve your configuration. Common problems include missing intermediate certificates or weak encryption algorithms, both of which can be resolved by adjusting your server settings.

Mixed content warnings

Mixed content warnings occur when a secured HTTPS page loads resources over an unsecured HTTP connection. This can undermine the security of your site. To resolve these warnings, update all internal links to use HTTPS. For WordPress sites, you can use the Really Simple SSL plugin to automate this process and ensure all content is served securely.

Mixed content can occur when images, scripts, or stylesheets are loaded over HTTP on an HTTPS page. This not only triggers browser warnings but also compromises the security of your site. To address this, first identify all HTTP resources by checking your site's source code or using browser developer tools. Manually update these URLs to HTTPS in your site's code or database. For WordPress users, the Really Simple SSL plugin simplifies this process by automatically detecting and updating all HTTP URLs to HTTPS. After making these changes, clear your site's cache and reload the page to verify that the warnings have been resolved. Regularly audit your site for mixed content, especially after adding new content or plugins, to maintain a secure environment.

Troubleshooting

If AutoSSL fails to issue a certificate, check that your domain is correctly pointed to GHost Cloud's nameservers: ns1.geeklab.host and ns2.geeklab.host. If your SSL certificate has expired, ensure AutoSSL is enabled and your domain is active. For browser 'Not Secure' warnings, verify that your certificate is installed correctly and there are no mixed content issues.

Start troubleshooting by confirming that your domain's DNS records point to the correct nameservers. Use tools like WHOIS or DNS checkers to verify this information. If AutoSSL is not issuing a certificate, ensure that your domain is fully propagated and active. An expired SSL certificate may indicate that AutoSSL is disabled or failed to renew the certificate. In such cases, manually trigger a renewal in the SSL/TLS Status section of cPanel. For 'Not Secure' warnings, double-check the installation of your SSL certificate and ensure there are no mixed content issues by following the steps outlined in the previous section. If problems persist, consult your hosting provider's support team for further assistance.

Related guides

You may also find it helpful to getting started with your hosting account using our step-by-step guide.

You may also find it helpful to point your domain to ghost cloud using our step-by-step guide.

You may also find it helpful to force https on your website using our step-by-step guide.

To enhance your website's security and trustworthiness, consider purchasing an SSL certificate from our SSL Certificates store. For further assistance, please contact us through our contact page or submit a support ticket.

Was this answer helpful? 0 Users Found This Useful (0 Votes)