Emergency server help: get in touch

cPanel AutoSSL Provider: Sectigo or Let’s Encrypt, Best Choice

How to choose and configure the AutoSSL provider on a cPanel server, enable the short-lived ACME certificate option introduced in version 136, and confirm that renewals happen well ahead of the shrinking industry lifetimes.

Published Updated 6 min read

AutoSSL issues and renews certificates for every domain on a cPanel server without customer involvement, and in 2026 it matters more than ever: the CA/Browser Forum has cut maximum certificate lifetimes to 200 days from March 2026, with 100 days in 2027 and 47 days in 2029 to follow. cPanel & WHM 136 responded by making Sectigo the default AutoSSL provider, keeping Let’s Encrypt as an option, and adding short-lived ACME certificates that renew automatically on a roughly 200-day cycle. This guide covers picking a provider, turning on short-lived certificates and checking that the machinery works.

Short answer: Open WHM → SSL/TLS → Manage AutoSSL, pick Sectigo (the default from version 136 and the safer choice on servers with many domains) or Let’s Encrypt, then enable the short-lived certificate option under the Options tab. Run /usr/local/cpanel/bin/autossl_check --all to reissue immediately and check the Logs tab for a success line per domain. Keep the daily AutoSSL cron and outbound HTTPS unblocked so the roughly 200-day certificates renew on time.

Choose a provider

Open WHM → SSL/TLS → Manage AutoSSL. The Providers tab lists what is available on your build. On 136 and later the default is Sectigo via ACME; Let’s Encrypt appears as an alternative once you accept its terms of service. Both issue domain-validated certificates at no cost, both support wildcard issuance through DNS validation where the zone is hosted locally, and both are subject to the same lifetime rules.

The practical differences are rate limits and validation behaviour. Let’s Encrypt applies per-registered-domain issuance limits that a large reseller server can hit when hundreds of subdomains renew in the same week. Sectigo’s ACME endpoint as used by cPanel does not apply the same public rate limits, which is why cPanel chose it as the default. If you run a server with many domains per account, Sectigo is the safer default; if you have a specific reason to prefer Let’s Encrypt, the switch is a radio button and the next AutoSSL run reissues under the new provider.

From the shell:

whmapi1 get_autossl_providers
whmapi1 set_autossl_provider provider=cPanel

The provider identifier for the Sectigo integration is cPanel in the API, and LetsEncrypt for the other option. Check the output of the first command for the exact names on your build.

Enable short-lived ACME certificates

On 136 and later, Manage AutoSSL → Options includes a setting for short-lived certificates. Enabling it tells the provider to issue certificates with a shorter validity, currently around 200 days, and AutoSSL reissues them automatically when they approach expiry. This is a deliberate move towards the 2027 and 2029 lifetimes, and enabling it now means your renewal process is tested long before it becomes mandatory.

Turn it on in the interface, or with the API where the option is exposed on your build; check whmapi1 get_autossl_options for the current option list, as names have changed between releases. Once enabled, the next AutoSSL run replaces long-lived certificates as they come due rather than all at once, so there is no thundering herd.

The other options on that page are worth reviewing at the same time. Leave “Allow AutoSSL to replace invalid or expiring non-AutoSSL certificates” enabled unless you sell paid certificates on the same server, and set the notification level so that customers are told when a domain repeatedly fails validation rather than every time it succeeds.

Enable AutoSSL for accounts and run it

AutoSSL applies to accounts through their feature list. In Manage AutoSSL → Manage Users, enable it for all users, or per user from the shell:

whmapi1 set_autossl_metadata_key key=clobber_externally_signed value=1
/usr/local/cpanel/bin/autossl_check --all

The autossl_check script runs the full pass immediately rather than waiting for the daily cron. For a single account:

/usr/local/cpanel/bin/autossl_check --user=<username>

Progress and problems appear in WHM → SSL/TLS → Manage AutoSSL → Logs. A successful run lists each domain, the validation method and whether a certificate was ordered or renewed.

How validation works and what to keep clear

AutoSSL validates each domain by HTTP, placing a token under /.well-known/pki-validation/ or /.well-known/acme-challenge/ on the document root, and falling back to DNS validation when the zone is hosted on the server. Anything that interferes with those requests breaks issuance: a .htaccess rule that redirects everything to HTTPS or to index.php, a CDN that serves cached 404s, a CAA record that names a different CA, or a firewall rule that blocks the validator. The troubleshooting side is covered in AutoSSL failed: fixing DCV errors, CAA records and CDN proxies.

Let the server’s own hostname be covered as well. WHM → Service Configuration → Manage Service SSL Certificates shows the certificates for cpsrvd, Exim, Dovecot and FTP. When AutoSSL issues the hostname certificate it can install it on those services automatically; run /usr/local/cpanel/bin/checkallsslcerts to force that check.

Verify

Confirm the provider, run a check, and inspect a certificate:

whmapi1 get_autossl_provider
/usr/local/cpanel/bin/autossl_check --user=<username>
echo | openssl s_client -servername example.com -connect example.com:443 2>/dev/null \
  | openssl x509 -noout -issuer -dates

The issuer should name Sectigo or Let’s Encrypt, and the dates should match the expected lifetime. Our SSL expiry check script walks every domain on the server and alerts on anything within a threshold, which is the check you want running weekly now that lifetimes are short.

Common pitfall

The mistake we see most often is enabling short-lived certificates and then blocking the daily AutoSSL cron, whether by disabling /etc/cron.d/cpanel_autossl, restricting outbound HTTPS, or leaving a CAA record for a previous provider. With long-lived certificates that mistake goes unnoticed for months; with a 200-day certificate it produces an outage. After any provider change, watch the AutoSSL log for the next two runs and confirm the renewals actually complete.

CPanel AutoSSL provider at a glance

cPanel AutoSSL Provider summary card: Open WHM → SSL/TLS → Manage AutoSSL, pick Sectigo (the default from version 136 and the safer choice on servers with…
In short: Open WHM → SSL/TLS → Manage AutoSSL, pick Sectigo (the default from version 136 and the safer choice on servers with many domains) or Let’s Encrypt, then enable the short-lived certificate option under the Options tab.

Official documentation: Let’s Encrypt documentation, cPanel & WHM documentation, Linux man pages.

Related guides: Using WP Toolkit Security Risk scores, Smart Update and Vulnerable Components · Certificate lifetimes are shrinking to 47 days: what hosting providers must automate now · LiteSpeed cPanel plugin CVE-2026-48172: the symlink-to-root flaw and how to verify you’re patched.

Frequently asked questions

Does switching the AutoSSL provider reissue every certificate at once?

No. Existing certificates stay installed until they approach expiry, and AutoSSL replaces each one under the new provider as it comes due, so the change causes no immediate outage or rate-limit burst.

How long does a short-lived AutoSSL certificate last?

As of cPanel 136 the short-lived option issues certificates valid for roughly 200 days, matching the CA/Browser Forum limit that took effect in March 2026; lifetimes drop to 100 days in 2027 and 47 days in 2029.

Can I switch back from Sectigo to Let’s Encrypt later?

Yes. Change the provider in Manage AutoSSL or with whmapi1 set_autossl_provider provider=LetsEncrypt, and future renewals use the new provider; check for CAA records that name only the previous CA first.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.