# SSL certificates

> Free Let's Encrypt certificates issued and renewed automatically, HTTPS redirects, wildcard certificates through your own DNS, and uploading a certificate you bought.

Source: https://zopanel.net/docs/ssl  
Updated: 2026-10-07

ZoPanel gives every website a free Let's Encrypt certificate and renews it for you. You manage certificates in the website's **SSL** tab (**Websites → Manage → SSL**).

## Before you start

- The administrator must set an **Administrator email** in **Settings**. Let's Encrypt registration uses it, and no certificate can be requested without it.
- Every name on the certificate (the domain and its aliases) must resolve to this server.
- Port 80 must be reachable from the Internet: certificates are validated over HTTP, through a challenge path that keeps working even when the site redirects to HTTPS, redirects everything elsewhere or is password-protected.

## Automatic certificates

When you create a website with **Free SSL (Let's Encrypt)** on, ZoPanel tries to issue the certificate right away. If the domain does not point to the server yet, the website still works over HTTP and the task log says so.

You do not need to come back and retry: every hour, ZoPanel looks for active websites with automatic SSL but no certificate and checks their DNS. As soon as the domain resolves only to this server, the certificate is issued. Aliases that still point elsewhere are left out, so they cannot make the whole order fail; they are added on the next issue. After a failed attempt, the next one for that website waits 2, 4, 8 hours and so on, up to a day, so Let's Encrypt rate limits are never wasted.

To issue or re-issue a certificate by hand, click **Issue certificate** (or **Re-issue**) on the **SSL** tab. The task log shows each step and a clear message when validation fails, for example when the domain does not resolve or port 80 is closed.

## Redirect HTTP to HTTPS

Once a certificate is installed, the **SSL** tab shows the issuer, the expiry date and two switches:

| Switch | Effect |
| --- | --- |
| **Redirect HTTP to HTTPS** | Every HTTP request gets a 301 redirect to HTTPS. ZoPanel also sends `Strict-Transport-Security: max-age=31536000`, so browsers remember to use HTTPS for one year. |
| **Auto renew** | Lets ZoPanel renew the certificate (on by default for Let's Encrypt). |

Because of the HSTS header, only turn on the redirect when you intend to keep HTTPS on that domain.

## Renewals

ZoPanel checks certificates every hour and renews Let's Encrypt certificates that expire within 30 days. If a renewal fails, it is retried after 1, 2, 4 and then 8 days (never more than a week apart), because Let's Encrypt limits failed attempts.

You are told when something needs attention:

- **SSL renewal failed**: sent to the administrator and to the website's owner, with the error.
- **SSL expiring soon**: sent once a day when a certificate expires within 14 days, which catches failing renewals and certificates installed by hand.

Customers choose these alerts in **My account → Notifications**. The dashboard also shows **SSL expiring soon** for certificates that expire within 14 days.

The most common reason a renewal fails is a domain that no longer points to this server. Fix DNS, then click **Re-issue**.

## Wildcard certificates

A wildcard certificate (`*.example.com`) covers every subdomain. Let's Encrypt only issues wildcards through DNS validation, so ZoPanel needs to control the domain's DNS:

1. The administrator installs the DNS server (see [DNS](/docs/dns)).
2. Create the zone for the domain on the **DNS** page and set this server's nameservers at the registrar.
3. On the website's **SSL** tab, tick **Also \*.example.com (wildcard)** and click **Issue certificate**.

The certificate covers `example.com` and `*.example.com`. Aliases already covered by the wildcard (for example `www.example.com`) are dropped from the order, because Let's Encrypt refuses redundant names; other aliases are kept. Renewals keep the wildcard. If the zone is not hosted on this server, ZoPanel refuses the request with a message that points you to the DNS page.

## Upload your own certificate

To use a certificate from another provider (for example an EV or OV certificate):

1. On the **SSL** tab, find **Custom certificate**.
2. Paste the **Certificate (incl. chain)** in PEM format: your certificate first, then the intermediate certificates.
3. Paste the **Private key** in PEM format.
4. Click **Install certificate**.

ZoPanel checks that the key matches the certificate, that the certificate is valid for the website's domain and that it has not expired. Only the certificates are written to the world-readable chain file; the private key is stored separately with restricted permissions.

A custom certificate turns **Auto renew** off, so ZoPanel does not replace it with Let's Encrypt. Renew it with your provider and install the new one before it expires; the 14-day expiry alert reminds you.

If the domain's zone is hosted on this server, note that new zones get a CAA record that allows only Let's Encrypt (`0 issue "letsencrypt.org"`). Add a CAA record for your other certificate authority on the **DNS** page before ordering from it.

## Disable SSL

**Disable SSL** removes HTTPS from the website and turns the HTTP-to-HTTPS redirect off. Visitors who already received the HSTS header keep trying HTTPS until it expires, so prefer re-issuing a certificate over disabling SSL on a live site.

## The panel's own certificate

The panel itself (port 8888) gets a trusted certificate from **Settings → Panel domain & SSL**. Point the panel domain to the server, then click **Issue certificate**. This certificate is also used by the mail server and webmail, and it is renewed automatically like website certificates.
