Skip to main content

SSL Setup

How to Install an SSL Certificate, Free or Paid

Whether you're using cPanel's AutoSSL, free Let's Encrypt, or a paid certificate that needs a manually generated CSR, here's the exact path for each.

Free

Auto-renewing SSL via AutoSSL

Minutes

Typical free certificate issuance time

24/7

Human support for CSR/install issues

30-day

Money-back guarantee

In short

To install an SSL certificate, the fastest route on cPanel-style hosting is enabling AutoSSL, which automatically issues and installs a free Let's Encrypt certificate for every domain with no manual steps. For a paid certificate, you first generate a CSR (Certificate Signing Request) from the panel, submit it to the certificate authority along with domain verification, then upload the returned certificate files back into the panel's SSL/TLS section once issued.

After installation, confirm the certificate covers the exact domain (and www version) in use, and update any hardcoded HTTP links so the whole site actually loads over HTTPS.

Installing an SSL certificate sounds like a server-admin task, but on modern hosting it's usually a few clicks, not a command line. The method differs mainly by whether you're using a free automated certificate or a paid one that requires manual verification and file uploads. Free Let's Encrypt certificates, issued through a panel feature usually called AutoSSL, handle domain validation and renewal entirely in the background — you turn it on once and never touch it again.

Paid certificates (typically OV or EV level, chosen when a business wants verified identity information embedded in the certificate) require an extra step: generating a CSR, a block of encoded text that identifies your domain and organization, which you submit to the certificate authority as part of applying. This guide covers both paths end to end, plus what to check immediately after installation to confirm HTTPS is actually working sitewide.

Installing Free SSL via cPanel AutoSSL / Let's Encrypt

In a cPanel-style panel, look for the SSL/TLS Status or AutoSSL section under Security. Selecting the domain and clicking Run AutoSSL triggers an automated process: the system proves domain ownership (usually by placing a verification file the certificate authority checks), requests a free Let's Encrypt certificate, and installs it directly onto the domain, all without leaving the panel. This typically completes within a few minutes for a standard domain.

The real advantage of AutoSSL over a manually installed certificate is renewal: Let's Encrypt certificates are valid for 90 days, and AutoSSL renews them automatically before expiry, which is exactly the mechanism behind hosting that advertises free auto-renewing SSL. There's nothing to schedule and nothing that silently lapses.

Generating a CSR for a Paid Certificate

If you're installing a paid OV or EV certificate, the certificate authority needs a CSR before it can issue anything. In the panel's SSL/TLS section, use Generate a Certificate Signing Request, entering the exact domain name, along with organization details if applying for OV or EV verification. This generates two things: the CSR itself, which you paste into the certificate authority's order form, and a private key, which stays on the server and must never be shared or uploaded anywhere else.

The certificate authority uses the CSR to verify you control the domain (and, for OV/EV, to verify the business exists), a process that can take anywhere from minutes for DV to several business days for EV, depending on how much documentation they require.

Installing the Certificate Once It's Issued

Once the certificate authority approves the request, they'll send back the certificate file (and often an intermediate/chain certificate). Back in the panel's SSL/TLS section, choose Install an SSL Certificate on the Domain, paste in the certificate and the CA bundle/intermediate certificate they provided, and submit. The panel matches this against the private key it generated earlier, and if everything lines up, the domain is now serving that certificate.

A mismatch here — installing the wrong certificate, or one for a different domain — produces a browser warning rather than a working padlock, so it's worth loading the site in an incognito window immediately after installing to confirm the certificate details match what you expect before considering the job done.

Confirming HTTPS Actually Works Sitewide

A newly installed certificate only secures the connection when the browser is actually requesting the HTTPS version of a page. Visit the site directly over HTTP afterward and confirm it either redirects to HTTPS or at minimum still loads without errors, and check for mixed-content warnings, which appear when an HTTPS page still loads an image, script, or stylesheet over plain HTTP.

Mixed content typically comes from hardcoded 'http://' links inside old page content, theme files, or plugin settings. Most site builders and WordPress plugins have a setting or search-and-replace tool to fix these in bulk rather than manually editing every page, and it's worth running that check right after any SSL installation, not weeks later when a visitor reports the padlock looks broken.

How to Install an SSL Certificate on Your Site

Free SSL Installed Automatically, No CSR Required

Most sites never need to touch a CSR at all. Free, auto-renewing SSL through AutoSSL covers standard domain validation with zero manual steps, which is what's included as standard on every Hosting Cheap plan.

If a business specifically needs OV or EV verification for compliance or brand reasons, generating a CSR and installing a paid certificate is still fully supported, with 24/7 human support if any step needs a second pair of eyes.

  • Free SSL issued and installed automatically, no CSR needed
  • 90-day Let's Encrypt certificates renewed before they ever expire
  • CSR generation available in-panel for paid OV/EV certificates
  • 24/7 support to troubleshoot mismatched or unrecognized certificates

Why Hosting Cheap

What you get

One-click AutoSSL installation

Free Let's Encrypt certificates install without generating a CSR or leaving the panel.

Automatic renewal

Certificates renew before their 90-day expiry with no manual step required.

CSR generation for paid certificates

Generate a CSR in-panel when a paid OV or EV certificate is required.

cPanel-style SSL/TLS management

Install, view, and manage certificates from one straightforward panel section.

24/7 human support

Help available if a certificate fails to install or shows a domain mismatch.

30-day money-back guarantee

Confirm SSL installs and HTTPS works exactly as expected, risk-free.

How It Works

Get set up in a few steps

1

Turn on AutoSSL for free certificates

Enable AutoSSL in the panel to issue and install a free Let's Encrypt certificate automatically.

2

Generate a CSR for paid certificates

If using a paid OV/EV certificate, generate a CSR in-panel and submit it to the certificate authority.

3

Install and verify

Upload the issued certificate files, then check the live site loads over HTTPS with no mixed-content warnings.

Included

Everything you need, on every plan

  • AutoSSL enabled for automatic free certificate issuance
  • CSR generated correctly if applying for a paid certificate
  • Private key kept secure and never shared with the certificate authority
  • Certificate and CA bundle uploaded and matched to the correct domain
  • HTTP requests redirect cleanly to HTTPS
  • No mixed-content warnings on any page
  • Certificate renewal confirmed as automatic, not manual

FAQ

Frequently asked questions

Do I need to generate a CSR for free SSL?

No. AutoSSL and Let's Encrypt handle domain-validated certificates entirely automatically, without requiring you to generate or submit a CSR yourself.

What is a CSR and when do I need one?

A CSR (Certificate Signing Request) is an encoded file identifying your domain, generated in-panel, that you submit to a certificate authority when applying for a paid OV or EV certificate.

How long does SSL installation take?

Free AutoSSL certificates typically install within minutes. Paid OV certificates can take from a few hours to a couple of business days, and EV certificates can take several business days due to the additional business verification required.

Why does my site still show 'Not Secure' after installing SSL?

This usually means either the certificate hasn't finished propagating, the site isn't redirecting HTTP to HTTPS, or there's mixed content on the page loading insecure resources. Check the panel's SSL status and scan the page for HTTP-linked images or scripts.

Can I install a certificate I bought elsewhere on Hosting Cheap?

Yes, third-party certificates can be installed through the panel's SSL/TLS section using the certificate, CA bundle, and matching private key or CSR generated on the account.

What happens if my SSL certificate expires?

Browsers will show visitors a security warning and most will refuse to proceed to the site. Free certificates through AutoSSL renew automatically before this happens, which is the main reason to prefer it over manually managed certificates.

Get SSL Installed Automatically

Every Hosting Cheap plan issues and renews free SSL automatically, from $2.09/mo.

Get Started