Installing on cPanel

Comprehensive Guide to SSL Certificates: Everything You Need to Know

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (9 sections)

An SSL certificate is what puts the padlock and https:// in front of your website. It lets the visitor's browser check that it is talking to your real server and encrypts everything sent between them. This guide explains how certificates work, the types you will hear about, how to get one, and how to avoid the common problems.

Key takeaways

An SSL certificate proves a website's identity and enables an encrypted HTTPS connection. For most websites a free, domain-validated certificate from Let's Encrypt is all you need, and almost every Domain India hosting plan includes one: it is issued automatically on cPanel (AutoSSL) and DirectAdmin, and you request it once on Plesk. Paid organisation-validated certificates add verified company details, which some banks, partners and tenders ask for. After installing, redirect HTTP to HTTPS and fix any mixed-content warnings.

1. What an SSL certificate is

A certificate is a small data file, signed by a trusted certificate authority (CA), that links a domain name to a cryptographic key. The server keeps the matching private key secret. When a browser connects, the server shows the certificate, and the browser checks three things:

  • that a CA it trusts signed it;
  • that it covers the exact name in the address bar;
  • that it has not expired or been revoked.

If all three pass, the browser shows the padlock and encrypts the session. If any fails, the visitor sees a full-page warning.

"SSL" is the old name. The protocol in use today is TLS (versions 1.2 and 1.3); SSL itself was retired years ago. People still say "SSL certificate", and the certificate is the same either way.

2. Why every website needs one

  • Privacy. Logins, form submissions, card details and personal data can't be read or altered on the way.
  • No "Not secure" label. Browsers mark every plain http:// page as not secure, and most visitors leave.
  • Search. Google uses HTTPS as a ranking signal.
  • Modern features. Browsers allow HTTP/2, HTTP/3, geolocation, service workers and many other features only over HTTPS.

3. How the secure connection works

  1. Hello.
    The browser connects and lists the TLS versions and ciphers it supports.
  2. Certificate.
    The server sends its certificate and the CA's intermediate certificates.
  3. Verification.
    The browser checks the signature chain up to a root CA it trusts, the domain name and the dates.
  4. Key agreement.
    Browser and server agree on a fresh session key. Only the server that holds the private key can complete this step.
  5. Encrypted traffic.
    Every request and response is encrypted with the session key.

With TLS 1.3 this takes a single round trip, so HTTPS adds almost no delay.

4. Types of certificates

Certificates differ in how much the CA checks and how many names they cover. The encryption is the same in all of them.

TypeWhat the CA verifiesGood for
Domain Validated (DV)Only that you control the domainAlmost every website, blog and shop
Organisation Validated (OV)The domain plus your organisation's legal detailsWhen a bank, partner or tender asks for verified company details
Extended Validation (EV)A stricter organisation checkSpecific compliance requirements; browsers no longer show a special green bar

And by coverage:

Single domain
Covers one name, often both example.com and www.example.com.
Multi-domain (SAN)
One certificate lists several names, such as example.com, shop.example.com and example.in.
Wildcard
Covers every first-level subdomain, *.example.com. It needs DNS validation.

For a deeper comparison, see Wildcard vs single-domain SSL.

5. Certificates are getting shorter

The industry rules that browsers enforce are shortening certificate lifetimes step by step. Since 15 March 2026 a publicly trusted certificate can be valid for at most 200 days; the limit falls to 100 days in March 2027 and 47 days in March 2029. Let's Encrypt certificates already last 90 days or less.

The practical effect: renewal must be automatic. Free certificates on hosting control panels already renew themselves. If you buy a certificate and install it by hand, you will have to replace it more and more often.

6. How to get a certificate

Free, automatic (recommended). On most hosting, the control panel requests a Let's Encrypt certificate for you once your domain points at the server, and renews it before it expires. You don't need a CSR or any payment.

Bought from a certificate authority. Use this only when someone requires OV or EV:

  1. Generate a CSR
    (certificate signing request) in your control panel. The panel creates the private key and keeps it on the server. See how to generate a CSR.
  2. Order from the CA
    and paste in the CSR.
  3. Complete validation
    by email, a DNS record or a file on your site; OV and EV also check company documents.
  4. Install
    the certificate and the CA bundle (intermediate certificates) in your control panel.
  5. Test
    the site over https:// and note the expiry date, because you renew it with that CA.
Never share your private key

The CSR and the certificate are public and safe to send. The private key is not. No certificate authority or support team needs it. If it has been emailed or pasted into a chat, generate a new key and CSR and have the certificate reissued.

7. After installing: best practices

  • Redirect HTTP to HTTPS so every visitor gets the secure version. See how to redirect non-www to www, which also covers HTTPS.
  • Cover www too. Make sure DNS for both example.com and www.example.com points at your hosting so the certificate includes both.
  • Update your CMS. In WordPress, set both addresses under Settings › General to https://.
  • Consider HSTS once HTTPS works everywhere. It tells browsers to always use HTTPS for your domain. Start with a short max-age, because a mistake is hard to undo.
  • Test from outside. A free checker such as Qualys SSL Labs shows the chain, protocols and any weak settings.

8. Common problems and fixes

SymptomLikely causeFix
"Not secure" or padlock with a warningMixed content: images, scripts or CSS loaded over http://Change those URLs to https:// or to relative paths
"Your connection is not private"Certificate expired, or it does not cover this nameRenew, or reissue it to include the name (often www)
Works on desktop, fails on some phonesMissing intermediate certificateInstall the full CA bundle with the certificate
Free certificate never issuedDomain or www not pointing at the hosting, a CAA record, or a proxy blocking the checkFix DNS, allow letsencrypt.org in CAA, pause the proxy while it issues

9. SSL on Domain India hosting

Almost every Domain India hosting plan includes free SSL: Let's Encrypt on cPanel (AutoSSL) and DirectAdmin, issued and renewed automatically once the domain points at your hosting, and Let's Encrypt on Windows (Plesk), which you request once in the panel and which then renews itself. You don't need to buy a certificate for the padlock. Domain India doesn't sell SSL certificates, so if a partner requires an OV or EV certificate, buy it from any CA and install it on your hosting yourself.

Step-by-step guides: AutoSSL in cPanel, Let's Encrypt in DirectAdmin, SSL in Plesk and ordering an SSL certificate.

What is an SSL certificate?

It is a digital certificate, signed by a trusted certificate authority, that links a domain name to a key held by the server. Browsers use it to confirm the site's identity and to set up an encrypted HTTPS connection.

Is a free SSL certificate as secure as a paid one?

Yes. The encryption is the same. Paid organisation-validated and extended-validation certificates add verified company details, which some banks, payment partners and tenders require, but they do not encrypt any better.

Does Domain India hosting include SSL?

Yes. Almost every Domain India hosting plan includes free SSL: AutoSSL with Let's Encrypt on cPanel, and Let's Encrypt on DirectAdmin and Windows (Plesk). It renews automatically while your domain points at the hosting.

Does Domain India sell paid SSL certificates?

No. Domain India does not sell SSL certificates. The free Let's Encrypt certificate included with almost every Domain India hosting plan covers almost every website; if you need an organisation-validated or other paid certificate, buy it from any certificate authority and install it on your hosting.

How long is an SSL certificate valid?

Since 15 March 2026 publicly trusted certificates can be valid for at most 200 days, falling to 100 days in 2027 and 47 days in 2029. Let's Encrypt certificates last 90 days or less and renew automatically on hosting control panels.

Why does my site still show "Not secure" after installing SSL?

Usually the page loads some images, scripts or stylesheets over http://. Change those links to https://, and redirect all HTTP traffic to HTTPS.

What is the difference between SSL and TLS?

TLS is the modern version of the protocol; SSL is its retired predecessor. Websites today use TLS 1.2 or 1.3, but the certificates are still commonly called SSL certificates.

Ready to secure your site? Check your certificate from your hosting services, read ordering an SSL certificate, or open a ticket if the free certificate won't issue.

Free SSL with every hosting plan

AutoSSL issues and renews a free Let's Encrypt certificate for your cPanel site automatically once your domain points at us.

See hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
SSL Certificates Explained: Types, How They Work, Setup