WHM (Web Host Manager) is the management panel for cPanel servers and offers comprehensive tools for SSL certificate management at the server level. In this guide, we explain in detail SSL installation via WHM, AutoSSL configuration, SNI settings and multi-client SSL management.
1. Installing SSL Certificate from WHM
Step 1: SSL Installation Page
- Login to WHM as root (https://server-ip:2087)
- Open the "SSL/TLS" section from the left menu
- Click "Install an SSL Certificate on a Domain"
Step 2: Entering Certificate Information
- Domain: Enter the domain name where you will install SSL
- Certificate (CRT): Paste the contents of the certificate file
- Private Key (KEY): Auto-fill or manual paste
- Certificate Authority Bundle (CABUNDLE): Intermediate certificate
- Click the "Install" button
2. AutoSSL Configuration (WHM)
AutoSSL is a powerful feature that provides automatic DV SSL certificate to all domains on the server.
AutoSSL Provider Selection
- WHM → "SSL/TLS" → "Manage AutoSSL"
- Provider options:
- cPanel (Sectigo): 90-day DV SSL
- Let's Encrypt: Free DV SSL
- Select your preferred provider and "Save"
AutoSSL Operation and Monitoring
# Running AutoSSL manually (SSH)
/usr/local/cpanel/bin/autossl_check --all
# For a specific user
/usr/local/cpanel/bin/autossl_check --user=cpuser
# Checking AutoSSL logs
tail -f /var/log/apache2/autossl_provider.log
3. SNI Configuration
Server Name Indication (SNI) allows using multiple SSL certificates on a single IP address.
| Feature | SNI | Dedicated IP |
|---|---|---|
| IP Requirement | Shared IP is sufficient | Separate IP for each domain |
| Browser Support | All modern browsers | All browsers |
| Cost | Low | High (additional IP fee) |
| Performance | No noticeable difference | No noticeable difference |
4. Multi-Domain SSL Management
Viewing SSL Status of All Domains
- WHM → "SSL/TLS" → "SSL/TLS Status"
- View SSL status of all domains on the server
- Filters: Current, Expired, No SSL, AutoSSL pending
Bulk SSL Management (API)
# SSL setup with WHM API
whmapi1 installssl domain=example.com\
crt="$(cat /path/to/cert.crt)" \
key="$(cat /path/to/cert.key)" \
cab="$(cat /path/to/ca-bundle.crt)"
# Querying SSL information
whmapi1 fetch_ssl_info domain=example.com
5. Server Level SSL (Hostname SSL)
- WHM → "Service Configuration" → "Manage Service SSL Certificates"
- You can assign an SSL certificate for each service:
- cPanel/WHM (2083/2087 ports)
- Mail (SMTP, IMAP, POP3)
- FTP (FTPS)
- Exim (Sending e-mail)
- Dovecot (E-mail reception)
- Enter certificate, private key and CA bundle information
- Click the "Install" button
6. Common Errors and Solutions
| Error | Solution |
|---|---|
| AutoSSL "DCV check failed" | Check that the domain DNS is directed to the server IP |
| SSL shows another domain | Check SNI configuration, restart Apache/Nginx |
| Port 443 blocked | Open port 443 in the firewall (if you use CSF, add 443 to the TCP_IN list) |
| AutoSSL not working | cron check: crontab -l | grep autossl |
Frequently Asked Questions
Does AutoSSL in WHM automatically install SSL on all domains?
Yes, when AutoSSL is enabled, the DV SSL certificate is automatically installed and renewed for all domains on the server.
Can I install custom SSL on customer accounts from WHM?
Yes, you can install any SSL certificate, including OV/EV, for any domain from the WHM → Install SSL Certificate page.
Is separate SSL required for the mail server?
Yes, separate SSL certificate or hostname SSL configuration is recommended for mail.example.com. You can do it from the WHM Service SSL section.