AutoSSL - Partial Renewal Failing
I'm getting "reduced coverage" notification emails from AutoSSL runs.
- I'm experiencing highly inconsistent AutoSSL behavior on cPanel 134.0.25. My setup intentionally removes DNS records for legacy addon-domain-generated subdomains because I do not use them and do not want them publicly resolving.
- Previously, AutoSSL would simply exclude failed DCV domains and renew the remaining valid SANs normally.
- Recently, AutoSSL started deferring the entire renewal due to failed DCV on those subdomains.
- To troubleshoot this, I manually deleted certificates for several domains and reran AutoSSL multiple times. The results appear completely inconsistent and randomized. One domain immediately received a clean replacement certificate, excluding the failed legacy subdomains. Another domain initially received no replacement certificate at all, then later successfully renewed all expected domains. A third domain repeatedly renews only partial coverage, but the exact set of covered domains changes between runs.
- For example, on some runs only
mail,webmail, andwwwreceive coverage, while the apex domain,cpanel,cpcontacts,cpcalendars, andwebdiskare skipped. On later runs, some of those domains may suddenly reappear while others disappear. The behavior does not appear deterministic. - HTTP DCV paths are publicly reachable and return normal 404 responses, so this does not appear to be a general connectivity issue.
- I’m also using Cloudflare as the edge proxy and recently enabled mTLS/Authenticated Origin Pulls. However, all ACME/DCV validation paths are explicitly exempted from Cloudflare rules, and the same infrastructure worked correctly for years prior to enabling mTLS. At this point I’m no longer convinced this is a Cloudflare issue because the same domains sometimes succeed and sometimes fail under identical conditions. Disabling mTLS didn't change anything.
- Has AutoSSL behavior regarding partial coverage changed recently? Previously, AutoSSL would simply exclude failed domains from renewal and continue issuing certificates for all remaining valid SANs. Now it appears to defer or process renewals inconsistently when some hostnames fail DCV.
-
Hey hey! I'm not aware of any changes to how those renewals happen. Since you're seeing inconsistent behavior it might be best to create a ticket with our team so we can look into this for you.
1 -
I'm with Namecheap, and I don't think I can contact the cPanel staff directly. At the same time, I have their self-managed hosting package, which means that although they provide the cPanel license, they do not offer technical support for it. I'm a bit unclear on what my options are here, since they license cPanel to me, are they still expected to provide at least some level of cPanel-related support? They said they aren't.
0 -
Correct - your license provider is *always* the main support contact, and then they escalate the issue to us if they can't resolve it.
1 -
Wrote to them. I'll let you know.
0 -
Hi Vatra,
I believe the AutoSSL interface has been moved within the last few updates.
Our customers no longer have access to the SSL/TLS Status module that was separate to the SSL/TLS Certificates module. Traditionally, this is where you would find the settings to deselect unwanted domains from AutoSSL.
I am still just familiarising myself with this but it appears that this feature set has been consolidated into the SSL/TLS Certificates module so maybe take a look there and see if you can find the AutoSSL coverage options you're looking for.
Cheers
Nathan0 -
Hi Nathan,
I know that, but the option to deselect isn't there anymore.
0 -
You likely want the details from the "134 and above" tab here: https://support.cpanel.net/hc/en-us/articles/360050034234-How-do-you-exclude-a-domain-from-AutoSSL
1 -
Thanks, that will be useful. I've excluded the unwanted hostnames. As for my provider, they will not offer support for this issue or any issue regarding cPanel: "We would like to clarify that while the cPanel support team may establish their own policies and regulations for licenses purchased directly through them, they are not able to influence or modify the terms of service governing our services."
0 -
I'm sure our team would love to hear more about that if you'd like to email cs@cpanel.net to speak with our Customer Service team :)
1 -
About my issue with AutoSSL, or about my provider not wanting to provide support?
0 -
Definitely the provider to let us know what is happening. I'm not sure how much we can do for the AutoSSL issue as there are per-license restrictions available with that tool as well.
1
Please sign in to leave a comment.
Comments
11 comments