SSL certificates
Free Let's Encrypt certificates issued and renewed automatically, HTTPS redirects, wildcard certificates through your own DNS, and uploading a certificate you bought.
ZoPanel gives every website a free Let's Encrypt certificate and renews it for you. You manage certificates in the website's SSL tab (Websites → Manage → SSL).
Before you start
- The administrator must set an Administrator email in Settings. Let's Encrypt registration uses it, and no certificate can be requested without it.
- Every name on the certificate (the domain and its aliases) must resolve to this server.
- Port 80 must be reachable from the Internet: certificates are validated over HTTP, through a challenge path that keeps working even when the site redirects to HTTPS, redirects everything elsewhere or is password-protected.
Automatic certificates
When you create a website with Free SSL (Let's Encrypt) on, ZoPanel tries to issue the certificate right away. If the domain does not point to the server yet, the website still works over HTTP and the task log says so.
You do not need to come back and retry: every hour, ZoPanel looks for active websites with automatic SSL but no certificate and checks their DNS. As soon as the domain resolves only to this server, the certificate is issued. Aliases that still point elsewhere are left out, so they cannot make the whole order fail; they are added on the next issue. After a failed attempt, the next one for that website waits 2, 4, 8 hours and so on, up to a day, so Let's Encrypt rate limits are never wasted.
To issue or re-issue a certificate by hand, click Issue certificate (or Re-issue) on the SSL tab. The task log shows each step and a clear message when validation fails, for example when the domain does not resolve or port 80 is closed.
Redirect HTTP to HTTPS
Once a certificate is installed, the SSL tab shows the issuer, the expiry date and two switches:
| Switch | Effect |
|---|---|
| Redirect HTTP to HTTPS | Every HTTP request gets a 301 redirect to HTTPS. ZoPanel also sends Strict-Transport-Security: max-age=31536000, so browsers remember to use HTTPS for one year. |
| Auto renew | Lets ZoPanel renew the certificate (on by default for Let's Encrypt). |
Because of the HSTS header, only turn on the redirect when you intend to keep HTTPS on that domain.
Renewals
ZoPanel checks certificates every hour and renews Let's Encrypt certificates that expire within 30 days. If a renewal fails, it is retried after 1, 2, 4 and then 8 days (never more than a week apart), because Let's Encrypt limits failed attempts.
You are told when something needs attention:
- SSL renewal failed: sent to the administrator and to the website's owner, with the error.
- SSL expiring soon: sent once a day when a certificate expires within 14 days, which catches failing renewals and certificates installed by hand.
Customers choose these alerts in My account → Notifications. The dashboard also shows SSL expiring soon for certificates that expire within 14 days.
The most common reason a renewal fails is a domain that no longer points to this server. Fix DNS, then click Re-issue.
Wildcard certificates
A wildcard certificate (*.example.com) covers every subdomain. Let's Encrypt only issues wildcards through DNS validation, so ZoPanel needs to control the domain's DNS:
- The administrator installs the DNS server (see DNS).
- Create the zone for the domain on the DNS page and set this server's nameservers at the registrar.
- On the website's SSL tab, tick Also *.example.com (wildcard) and click Issue certificate.
The certificate covers example.com and *.example.com. Aliases already covered by the wildcard (for example www.example.com) are dropped from the order, because Let's Encrypt refuses redundant names; other aliases are kept. Renewals keep the wildcard. If the zone is not hosted on this server, ZoPanel refuses the request with a message that points you to the DNS page.
Upload your own certificate
To use a certificate from another provider (for example an EV or OV certificate):
- On the SSL tab, find Custom certificate.
- Paste the Certificate (incl. chain) in PEM format: your certificate first, then the intermediate certificates.
- Paste the Private key in PEM format.
- Click Install certificate.
ZoPanel checks that the key matches the certificate, that the certificate is valid for the website's domain and that it has not expired. Only the certificates are written to the world-readable chain file; the private key is stored separately with restricted permissions.
A custom certificate turns Auto renew off, so ZoPanel does not replace it with Let's Encrypt. Renew it with your provider and install the new one before it expires; the 14-day expiry alert reminds you.
If the domain's zone is hosted on this server, note that new zones get a CAA record that allows only Let's Encrypt (0 issue "letsencrypt.org"). Add a CAA record for your other certificate authority on the DNS page before ordering from it.
Disable SSL
Disable SSL removes HTTPS from the website and turns the HTTP-to-HTTPS redirect off. Visitors who already received the HSTS header keep trying HTTPS until it expires, so prefer re-issuing a certificate over disabling SSL on a live site.
The panel's own certificate
The panel itself (port 8888) gets a trusted certificate from Settings → Panel domain & SSL. Point the panel domain to the server, then click Issue certificate. This certificate is also used by the mail server and webmail, and it is renewed automatically like website certificates.