Emergency server help: get in touch

cPanel SSL/TLS Interface (v136+): Install and Renew

cPanel & WHM 136 merged the separate SSL/TLS Manager, SSL/TLS Status and installation pages into one interface. This guide shows where each task moved, how to install a paid certificate, and the uapi equivalents for scripting.

Published Updated 7 min read

Before version 136, certificate work in cPanel was scattered across three places: SSL/TLS for keys, CSRs and installs, SSL/TLS Status for AutoSSL coverage, and a separate paid-certificate purchase flow. cPanel & WHM 136, released in April 2026, consolidated these into a single SSL/TLS interface that shows every domain on the account, its current certificate, who issued it, when it expires and what action is available. For administrators used to the old layout, the tasks are the same but the buttons moved. This guide maps the common jobs onto the new interface and the matching API calls.

Short answer: Open cPanel → Security → SSL/TLS; the domain list shows every name with its issuer, expiry and status, and expanding a row gives the actions that used to live on separate pages: run AutoSSL, exclude from AutoSSL, install a certificate, or download the certificate and key. Keys and CSRs sit under the Certificates and Keys panel, and a paid certificate is installed from the domain’s row or with uapi SSL install_ssl (or whmapi1 installssl as root). AutoSSL renewals need no action; force one with /usr/local/cpanel/bin/autossl_check --user=USERNAME.

What the unified page shows

Open cPanel → Security → SSL/TLS. The main view is a domain list. Each row shows the domain, whether it is secured, the certificate issuer (AutoSSL via Sectigo or Let’s Encrypt, a paid certificate, or self-signed), the expiry date, and a status indicator. Filters let you show only unsecured domains, only expiring ones, or only domains excluded from AutoSSL. Selecting a row expands to show the certificate details, the validation history for AutoSSL, and the available actions: run AutoSSL now, exclude from AutoSSL, install a certificate, or view and download the certificate and key.

The old sections have become tabs or panels within this page. Private keys, CSRs and uploaded certificates live under a “Certificates and Keys” panel; the AutoSSL log for the account is under the domain’s expanded row; and the paid certificate option appears as an action on unsecured or expiring domains where the provider is configured in WHM.

WHM side, the corresponding pages are unchanged in name: WHM → SSL/TLS → Manage AutoSSL for the provider and options, and WHM → SSL/TLS → Install an SSL Certificate on a Domain for administrator installs. What changed is that the WHM install page now lists the same certificate metadata the cPanel page does.

Install a purchased certificate

Start with a key and CSR. On the unified page open Certificates and Keys, generate a 2048-bit or larger RSA key or an ECDSA P-256 key, then generate a CSR for the domain. Send the CSR to the CA, and when the certificate comes back, return to the domain’s row and choose Install. Paste the certificate; the interface matches it to the stored key automatically and asks for the CA bundle if it is not embedded.

The same job from the shell, useful when a customer emails you a certificate bundle:

uapi --user=<username> SSL install_ssl domain=example.com \
  cert="$(cat /root/example.com.crt)" \
  key="$(cat /root/example.com.key)" \
  cabundle="$(cat /root/example.com.ca-bundle)"

Or as root through WHM’s API, which works for any account:

whmapi1 installssl domain=example.com \
  crt="$(cat /root/example.com.crt)" \
  key="$(cat /root/example.com.key)" \
  cab="$(cat /root/example.com.ca-bundle)"

Installing a paid certificate on a domain that AutoSSL also manages will, by default, cause AutoSSL to leave it alone until it is close to expiry, at which point the “replace invalid or expiring non-AutoSSL certificates” option in WHM decides what happens. If the customer intends to renew the paid certificate, exclude the domain from AutoSSL in the unified page so there is no surprise replacement.

View and export what is installed

Inspecting certificates is where the unified page saves the most time. The list gives you expiry at a glance, and the expanded row shows the full chain. To pull the same information for scripting:

uapi --user=<username> SSL installed_hosts --output=json
uapi --user=<username> SSL list_certs

The first call returns each virtual host with its certificate, issuer, validity and the domains it covers; the second lists stored certificates including ones not currently installed. For a whole-server view, whmapi1 fetch_ssl_vhosts returns every installed host, which is what our SSL expiry check script uses.

Exporting a certificate and key for use elsewhere, for example on a load balancer, is a download action on the row. Treat the key with the care it deserves and delete the downloaded copy when finished.

Renew and reissue

For AutoSSL-managed domains there is nothing to do; the daily run reissues as expiry approaches, and on 136 and later with short-lived certificates enabled that happens on a roughly 200-day cycle. When you want to force it, use “Run AutoSSL” on the domain row or:

/usr/local/cpanel/bin/autossl_check --user=<username>

For paid certificates, generate a new CSR from the existing key or a fresh key, obtain the new certificate, and install it over the old one; the interface replaces it in place. Remove superseded certificates from the store afterwards with the delete action or uapi SSL delete_cert, so the list stays readable.

Renewal of the server’s own service certificates for cpsrvd, Exim, Dovecot and FTP is a WHM task, under Service Configuration → Manage Service SSL Certificates, and is unaffected by the cPanel-side changes.

Verify

After an install or renewal, check from outside the server rather than trusting the interface:

echo | openssl s_client -servername example.com -connect example.com:443 2>/dev/null \
  | openssl x509 -noout -subject -issuer -dates

Confirm the subject and issuer are what you expect and the dates are new. Open the site in a browser and check the padlock, and if the domain sits behind a CDN, confirm the CDN’s origin certificate settings still match.

Common pitfall

The commonest confusion after 136 is customers reporting that “the SSL page is missing” because they were following an old tutorial. The interface is there; it is the layout that changed. The second, more serious, mistake is installing a paid certificate for example.com only and forgetting that AutoSSL previously covered www, mail and webmail subdomains on the same virtual host. A paid certificate without those names causes browser warnings on webmail the following day. Either buy a certificate that includes them, or leave AutoSSL covering the subdomains on a separate virtual host, and check uapi SSL installed_hosts to see exactly which names each certificate covers.

CPanel SSL/TLS interface at a glance

cPanel SSL/TLS Interface summary card: Open cPanel → Security → SSL/TLS; the domain list shows every name with its issuer, expiry and status, and expanding a…
In short: Open cPanel → Security → SSL/TLS; the domain list shows every name with its issuer, expiry and status, and expanding a row gives the actions that used to live on separate pages: run AutoSSL, exclude from AutoSSL, install a certificate, or…

Official documentation: Let’s Encrypt documentation, cPanel & WHM documentation, Linux man pages.

Related guides: Fix WordPress “cURL error 28: Failed to connect” caused by Imunify360 or CSF · CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws · Whitelist IPs and countries in Imunify360 from the CLI.

Frequently asked questions

Does the unified SSL/TLS interface change the WHM SSL pages?

The WHM pages keep their names: Manage AutoSSL and Install an SSL Certificate on a Domain are where they were, though the install page now shows the same certificate metadata the cPanel page does.

How long does a paid certificate install take through the new interface?

Once the CSR has been signed, pasting the certificate and CA bundle into the domain’s row installs it in seconds and Apache is reloaded automatically; an external openssl s_client check should show the new issuer straight away.

Can I stop AutoSSL replacing a paid certificate I installed?

Yes. Exclude the domain from AutoSSL in the domain’s row, or review the WHM option for replacing non-AutoSSL certificates; otherwise AutoSSL may reissue when the paid certificate nears expiry.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.