How to renew or reissue a Let's Encrypt SSL certificate in cPanel
Let's Encrypt certificates last only 90 days and usually renew themselves through AutoSSL. But when auto-renewal breaks (DNS changed, the domain was unreachable, conflicting records appeared), you have to renew by hand. Do it at the latest a few days before expiry.
Check your site
-
Check when the certificate expires
In cPanel open SSL/TLS Status. Each domain shows its expiry date and certificate source. A red or yellow status means it is time to act.
-
Run AutoSSL manually
On the same page click Run AutoSSL. cPanel contacts Let's Encrypt and reissues certificates for domains that pass validation. It usually takes a few minutes.
-
Find out why it did not renew on its own
If AutoSSL skips a domain, click its status and read the reason. Most often it is an unreachable domain, a redirect to another site, or DNS pointing away from this server.
-
Clear obstacles to validation
Let's Encrypt proves domain control through a file under /.well-known/acme-challenge/. Make sure redirects and .htaccess do not block that path and that the domain actually resolves to this server.
-
Reissue after the fix
Once the cause is gone, click Run AutoSSL again. A new expiry date in SSL/TLS Status confirms the certificate is renewed for another 90 days.
-
Do not mix in third-party certificates
If you once installed a manual certificate from another authority, remove the stale one under SSL/TLS > Manage SSL Sites so AutoSSL does not conflict and can install a fresh Let's Encrypt one.
How to verify the result
SSL/TLS Status should show a green status and an expiry date roughly 90 days out. You can quickly confirm the site serves the new certificate with the TechGuard SSL checker.
Tip: Do not wait for the last day: if auto-renewal is failing, you want time to investigate while the old certificate is still valid.
Related guides
Found problems?
Slow hosting, SSL trouble or frequent downtime? Move to TomisHost: fast hosting with free SSL, daily backups and free migration help.
TomisHost hosting