{"id":1037,"date":"2021-07-23T12:44:01","date_gmt":"2021-07-23T12:44:01","guid":{"rendered":"https:\/\/ssdsunucum.com\/blog\/manage-autossl\/"},"modified":"2021-07-23T12:44:01","modified_gmt":"2021-07-23T12:44:01","slug":"manage-autossl","status":"publish","type":"post","link":"https:\/\/ssdsunucum.com\/blog\/manage-autossl\/","title":{"rendered":"Manage AutoSSL"},"content":{"rendered":"<\/p>\n<div class=\"col-md-9\">\n<div class=\"flex-column flex-md-row article-header\">\n<div id=\"versioned-article-header\">\n<p class=\"valid-version-info\"><em>Valid for versions 88 through the latest version<\/em><\/p>\n<\/div>\n<div id=\"version-select-group\" aria-label=\"select versions\">\n<h4>Version:<\/h4>\n<h4>82<\/h4>\n<h4>84<\/h4>\n<h4>88<\/h4>\n<\/div><\/div>\n<hr>\n<h2 id=\"overview\">Overview<\/h2>\n<p>This interface allows you to manage the AutoSSL feature, which automatically installs domain-validated SSL certificates for the Apache\u00ae, Dovecot, Exim, Web Disk, and cPanel Server services for users\u2019 domains. It also allows you to review the feature\u2019s log files and select which users receive AutoSSL certificates.<\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<p>When AutoSSL runs, the system performs a preflight check. This check adds a Certificate Authority Authentication (CAA) record in the domain\u2019s zone file <strong>before<\/strong> AutoSSL orders a new certificate for that domain.<\/p>\n<\/p><\/div>\n<\/div>\n<h2 id=\"provider-information\">Provider information<\/h2>\n<p>The following information displays at the top of this interface:<\/p>\n<ul>\n<li>\n<p><em>Current Provider<\/em> \u2014 Your current AutoSSL provider.<\/p>\n<\/li>\n<li>\n<p><em>Provider Account ID<\/em> \u2014 Your account identification for your AutoSSL provider. If the selected provider does not have an account ID, the interface does <strong>not<\/strong> display this information.<\/p>\n<\/li>\n<li>\n<p><em>Run AutoSSL for All Users<\/em> \u2014 Click to run the AutoSSL feature for all users for whom you enabled the feature.<\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<ul>\n<li>The system runs the AutoSSL feature for all users at the following times:\n<ul>\n<li>When it performs nightly system updates via the <code>\/usr\/local\/cpanel\/scripts\/upcp<\/code> script.<\/li>\n<li>From the task queue after you create an account. AutoSSL examines the system\u2019s SSL coverage and requests certificates from the configured provider to improve the system\u2019s SSL coverage.<\/li>\n<\/ul>\n<\/li>\n<li>To run the AutoSSL feature for all users via the command line, run the <code>\/usr\/local\/cpanel\/bin\/autossl_check --all<\/code> command.<\/li>\n<\/ul><\/div>\n<\/div>\n<\/li>\n<\/ul>\n<h3 id=\"autossl-providers\">AutoSSL providers<\/h3>\n<h4 id=\"the-cpanel-powered-by-sectigo-provider\">The cPanel (powered by Sectigo) provider<\/h4>\n<p>By default, the system uses the <em>cPanel (powered by Sectigo)<\/em> provider. Your cPanel license includes this free provider.<\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<ul>\n<li>\n<p>This provider requires outbound access to the <code>store.cpanel.net<\/code> server over port <code>443<\/code>. For more information, read our How to Configure Your Firewall for cPanel &#038; WHM Services documentation.<\/p>\n<\/li>\n<li>\n<p>Certain factors may cause longer wait times. Under some conditions, these certificates may require up to 48 hours to process.<\/p>\n<\/li>\n<li>\n<p>This provider does <strong>not<\/strong> support wildcard domains.<\/p>\n<\/li>\n<\/ul><\/div>\n<\/div>\n<p>The system automatically polls this provider to determine each pending certificate\u2019s status:<\/p>\n<table>\n<thead>\n<tr>\n<th align=\"left\">Age of certificate request<\/th>\n<th align=\"left\">Polling frequency<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td align=\"left\">Less than 30 minutes.<\/td>\n<td align=\"left\">Once every two minutes.<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">After 30 minutes.<\/td>\n<td align=\"left\">Once every ten minutes.<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">After one hour.<\/td>\n<td align=\"left\">Once every 30 minutes.<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">After four hours.<\/td>\n<td align=\"left\">Once every hour.<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">After one day.<\/td>\n<td align=\"left\">Once every 12 hours.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n<p>This provider does <strong>not<\/strong> request additional signed certificates for a virtual host when:<\/p>\n<ul>\n<li>\n<p>The virtual host has a pending signed certificate request.<\/p>\n<\/li>\n<li>\n<p>There is an existing signed certificate for the virtual host.<\/p>\n<\/li>\n<li>\n<p>The virtual host\u2019s certificate has <strong>not<\/strong> expired.<\/p>\n<\/li>\n<\/ul><\/div>\n<\/div>\n<h4 id=\"the-let-s-encrypt-plugin\">The Let\u2019s Encrypt plugin<\/h4>\n<p>If you do not want to use the default AutoSSL provider, you can use the Let\u2019s Encrypt\u2122 plugin. This plugin allows AutoSSL to use Let\u2019s Encrypt as the AutoSSL certificate provider. For more information, read our Let\u2019s Encrypt Plugin documentation.<\/p>\n<h2 id=\"providers\">Providers<\/h2>\n<p>The <em>AutoSSL Providers<\/em> tab allows you to select which provider you want to manage your AutoSSL certificates. Click <em>Show\/Hide Details<\/em> to view a table with information about each provider. The system rates providers with a star icon. The system also determines a rating based on a provider\u2019s AutoSSL management capabilities.<\/p>\n<p>For example, an AutoSSL provider with a six-star score may look like the following:<\/p>\n<\/p>\n<p><center><br \/>\n<img style=\"width:100%\" src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/autossl-provider-stars.png\" title=\"autossl-provider-stars\"><br \/>\n<\/center><\/p>\n<p>The system assigns the <em>cPanel (powered by Sectigo)<\/em> provider\u2019s Usability Score by its ability to:<\/p>\n<ul>\n<li>Support the \u201c<em>http<\/em>\u201d and \u201c<em>dns<\/em>\u201d Domain Control Validation (DCV) method (two stars for each Ancestor DCV-supported DCV method, for a total of four stars).<\/li>\n<li>Provide 1,000 domains per certificate (one star).<\/li>\n<li>Offer an average delivery time of two minutes (one star).<\/li>\n<li>Provide an <em>unlimited<\/em> number of certificates per registered domain per week (one star).<\/li>\n<\/ul>\n<p>The <em>Show\/Hide Details<\/em> table contains the following:<\/p>\n<ul>\n<li>\n<p><em>Provider<\/em> \u2014  The AutoSSL provider. Select Disabled to disable the AutoSSL feature.<\/p>\n<\/li>\n<li>\n<p><em>Usability Score<\/em> \u2014 The total score of a provider, which its AutoSSL capabilities determine. This score is the sum of each provider\u2019s DCV Methods: <em>Ancestor DCV Support<\/em>, <em>Domains per Certificate<\/em>, <em>Average Delivery Time<\/em>, <em>Maximum Number of Redirects<\/em>, <em>Rate Limit<\/em>, and <em>Wildcard Support<\/em> capabilities. A provider can attain a rating up to nine stars.<\/p>\n<\/li>\n<li>\n<p><em>DCV Methods<\/em> \u2014 The DCV methods that the provider offers. A provider can receive a total of two stars per DCV method if they support Ancestor DCV. If they do not support Ancestor DCV, the provider receives one star per DCV method.<\/p>\n<\/li>\n<li>\n<p><em>Ancestor DCV Support<\/em> \u2014 Whether the successful DCV of a parent domain implies success of a subdomain. For example, if the <code>example.com<\/code> domain succeeds, then the DCV for the <code>store.example.com<\/code> subdomain is unnecessary.<\/p>\n<\/li>\n<li>\n<p><em>Domains per Certificate<\/em> \u2014 The number of unique domains per certificate. A provider can receive a total of one star.<\/p>\n<\/li>\n<li>\n<p><em>Delivery Method<\/em> \u2014 The means through which the provider issues a certificate, via the api, queue, or Unspecified method.<\/p>\n<\/li>\n<li>\n<p><em>Average Delivery Time<\/em> \u2014 The amount of time the provider requires to issue a certificate, if specified. A provider can receive a total of one star.<\/p>\n<\/li>\n<li>\n<p><em>Validity Period<\/em> \u2014 The period of time before the certificate expires, or Unspecified.<\/p>\n<\/li>\n<li>\n<p><em>Maximum Number of Redirects<\/em> \u2014 The maximum number of redirects a domain can use and still pass an HTTP-based DCV. A provider can receive a total of one star.<\/p>\n<\/li>\n<li>\n<p><em>Rate Limit<\/em> \u2014 The number of certificates the provider registers per domain per week, or Unspecified. A provider can receive a total of one star.<\/p>\n<\/li>\n<li>\n<p><em>Wildcard Support<\/em> \u2014 Whether the provider supports wildcard domains. A provider can receive a total of one star.<\/p>\n<\/li>\n<\/ul>\n<h3 id=\"terms-of-service\">Terms of Service<\/h3>\n<p>If the AutoSSL provider requires a Terms of Service or other similar agreement, review it and select the appropriate checkbox to agree to those terms.<\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<p>If a provider updates their Terms of Service, you may need to return to this interface to agree to them.<\/p>\n<\/p><\/div>\n<\/div>\n<h2 id=\"options\">Options<\/h2>\n<p>The <em>Options<\/em> tab allows you to configure various options for AutoSSL.<\/p>\n<h3 id=\"notifications\">Notifications<\/h3>\n<p>The notification options allow you to select the frequency at which your users receive AutoSSL-related notifications.<\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<ul>\n<li>\n<p>Some of these options remove the corresponding notification option in cPanel\u2019s <em>Contact Information<\/em> interface (<em>cPanel<\/em> &gt;&gt; <em>Home<\/em> &gt;&gt; <em>Preferences<\/em> &gt;&gt; <em>Contact Information<\/em>). For example, if you disable the <em>Notify the user for all AutoSSL events and normal successes<\/em> user notification setting, this option is unavailable to your cPanel users.<\/p>\n<\/li>\n<li>\n<p>These options override the user\u2019s current settings.<\/p>\n<\/li>\n<\/ul><\/div>\n<\/div>\n<h4 id=\"user-notifications\">User Notifications<\/h4>\n<p>You can select from the following notification options for your cPanel users:<\/p>\n<ul>\n<li>\n<p><em>Notify the user for <strong>all<\/strong> AutoSSL events and normal successes.<\/em><\/p>\n<\/li>\n<li>\n<p><em>Notify the user for AutoSSL certificate request failures, warnings, and deferrals.<\/em><\/p>\n<\/li>\n<li>\n<p><em>Notify the user for AutoSSL certificate request failures <strong>only<\/strong>.<\/em><\/p>\n<\/li>\n<li>\n<p><em>Disable AutoSSL user notifications.<\/em><\/p>\n<\/li>\n<\/ul>\n<p>This setting defaults to <em>Notify the user for AutoSSL certificate request failures, warnings, and deferrals.<\/em><\/p>\n<h4 id=\"administrator-notifications\">Administrator Notifications<\/h4>\n<p>You can select from the following notification options for your reseller and WHM users:<\/p>\n<ul>\n<li>\n<p><em>Notify the administrator for <strong>all<\/strong> AutoSSL events and normal successes.<\/em><\/p>\n<\/li>\n<li>\n<p><em>Notify the administrator for AutoSSL certificate request failures, warnings, and deferrals.<\/em><\/p>\n<\/li>\n<li>\n<p><em>Notify the administrator for AutoSSL certificate request failures <strong>only<\/strong>.<\/em><\/p>\n<\/li>\n<li>\n<p><em>Disable AutoSSL administrator notifications.<\/em><\/p>\n<\/li>\n<\/ul>\n<p>This setting defaults to <em>Notify the user for AutoSSL certificate request failures, warnings, and deferrals<\/em>.<\/p>\n<h3 id=\"allow-autossl-to-replace-invalid-or-expiring-non-autossl-certificates\">Allow AutoSSL to replace invalid or expiring non-AutoSSL certificates<\/h3>\n<p>This option allows AutoSSL to replace certificates that the AutoSSL system did <strong>not<\/strong> issue. When you enable this option, AutoSSL will install certificates that replace users\u2019 non-AutoSSL certificates if they are invalid or expire within three days.<\/p>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n<ul>\n<li>\n<p>Unless you fully understand this option, do <strong>not<\/strong> enable it, because the system may unexpectedly replace an expiring or invalid Extended Validation (EV) or Organization Validated (OV) certificate with a Domain Validated (DV) certificate.<\/p>\n<\/li>\n<li>\n<p>Users\u2019 non-AutoSSL certificates are paid, and should be replaced by another paid certificate.<\/p>\n<\/li>\n<\/ul><\/div>\n<\/div>\n<h2 id=\"logs\">Logs<\/h2>\n<p>Use the <em>Logs<\/em> tab to review the system\u2019s AutoSSL log files. To view a specific log, select it from the menu and click <em>View Log<\/em> to display the its information.<\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<p>The system stores the log files in both text and JSON format in the <code>\/var\/cpanel\/logs\/autossl<\/code> directory.<\/p>\n<\/p><\/div>\n<\/div>\n<h2 id=\"manage-users\">Manage Users<\/h2>\n<p>The <em>Manage Users<\/em> tab allows you to override your server\u2019s feature list settings and control whether AutoSSL is enabled for your users. Use the search text box to locate specific users, or use the check box and menu to select all users or clear your current selections.<\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<p>User feature lists may differ, based on the user\u2019s assigned package. For more information, read our Feature Manager documentation.<\/p>\n<\/p><\/div>\n<\/div>\n<p>You can select from the following Toggle AutoSSL options for individual users and select users:<\/p>\n<ul>\n<li>\n<p><em>Enable AutoSSL on selected users<\/em> \u2014 Override the feature list setting and force AutoSSL to be enabled.<\/p>\n<\/li>\n<li>\n<p><em>Disable AutoSSL on select users<\/em> \u2014 Override the feature list setting and force AutoSSL to be disabled.<\/p>\n<\/li>\n<li>\n<p><em>Reset AutoSSL on selected users<\/em> \u2014 Use setting established by the feature list\u2019s default setting. For more information, read our Feature Manager documentation.<\/p>\n<\/li>\n<\/ul>\n<h3 id=\"run-autossl-check\">Run AutoSSL Check<\/h3>\n<p>You can use the <em>Check<\/em> button to perform a domain check for a specific user.<\/p>\n<h2 id=\"pending-queue\">Pending Queue<\/h2>\n<p>The <em>Pending Queue<\/em> section of the interface lists the status and the details of the pending AutoSSL jobs on your server. Use the navigation controls at the top of the table to sort and search through the list.<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Valid for versions 88 through the latest version Version: 82 84 88 Overview This interface allows you to manage the AutoSSL feature, which automatically installs domain-validated SSL certificates for the Apache\u00ae, Dovecot, Exim, Web Disk, and cPanel Server services for users\u2019 domains. It also allows you to review the feature\u2019s log files and select which &hellip;<\/p>\n","protected":false},"author":1,"featured_media":1038,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/posts\/1037"}],"collection":[{"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/comments?post=1037"}],"version-history":[{"count":0,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/posts\/1037\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/media\/1038"}],"wp:attachment":[{"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/media?parent=1037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/categories?post=1037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/tags?post=1037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}