Skip to main content

SSL problems...

Comments

3 comments

  • cPanelMichael
    Hello @4u123, Self-signed certificates are automatically installed if a signed certificate (either manually installed or through AutoSSL) is not available as of cPanel version 62. Here's the relevant section from the cPanel 62 Release Notes: Automatically install best available certificate for new addon domain, parked domain, or subdomain When you create an addon domain, parked domain, or subdomain, the system will attempt to automatically secure that domain with an existing certificate. If no certificate exists within the domain"s virtual host, but another certificate matches the domain, the system will secure the domain with that certificate. If no certificate matches the domain, the system will install a self-signed certificate for the domain. All websites receive an SSL certificate Any website created in cPanel & WHM now receives an SSL certificate. A self-signed certificate is added if no other SSL certificates are available.
    cPanel version 66 includes an option to disable self-signed certificates. You can read about this on the following post: Problem with automatically generated self-signed SSL certificates
    Plus I see lots of expired AutoSSL certs. What's up with that?

    Can you browse to the "Logs" tab in "WHM >> Manage AutoSSL" and let us know what you see in the log files for the accounts with expired AutoSSL certificates? Thank you.
    0
  • 4u123
    Hello @4u123, Self-signed certificates are automatically installed if a signed certificate (either manually installed or through AutoSSL) is not available as of cPanel version 62.

    A typically stupid idea. What happens if you enable AutoSSL on a user that has already had self-signed certs automatically installed? Will the AutoSSL cert override the self-signed cert? Or will that need deleting manually first?
    0
  • cPanelMichael
    What happens if you enable AutoSSL on a user that has already had self-signed certs automatically installed? Will the AutoSSL cert override the self-signed cert? Or will that need deleting manually first?

    AutoSSL will automatically attempt to replace self-signed certificates when it's enabled on an account. EX:
    4:32:02 AM Checking websites for "cpusername" " 4:32:02 AM The website "domain.tld", owned by "cpusername", has a faulty SSL certificate (OPENSSL_VERIFY:0:18:DEPTH_ZERO_SELF_SIGNED_CERT NOT_ALL_DOMAINS). AutoSSL will attempt to replace this certificate.
    Thank you.
    0

Please sign in to leave a comment.