Control Center can request a free Let's Encrypt certificate after your website's DNS connection is confirmed. Hosting account creation starts after payment and domain confirmation; DNS can still point elsewhere at that stage. SSL is a separate step that needs working public validation.
- Open Hosting services → Manage website → DNS & SSL for the intended domain. Expand Get your hosting ready if the checklist is collapsed.
- Complete Connect your domain using either Keep my DNS provider or Use Lucid nameservers. The external-provider route uses the displayed records and Check DNS records. The Lucid route must confirm delegation and hosting records. Do not replace an existing provider's mail records unless you are moving email.
- Check that the site is reachable over HTTP. For this request, Let's Encrypt uses web validation on port 80. Ensure a password prompt, proxy, or application rule does not block the challenge. Supported redirects can work; a loop or wrong destination cannot. Let's Encrypt challenge types
- Under Secure your site, select Request Let’s Encrypt SSL. The service must be paid, active, unexpired, and DNS-ready. The request covers the selected domain only. It does not automatically add
www, wildcard names, mail, or the control-panel hostname. - Let the background request finish. If the page says the request is running, refresh in a few minutes. Requests are limited to one per ten minutes; another request is unavailable while one is queued.
- After success, open the selected domain with HTTPS and inspect the certificate's name and expiry. Automatic renewal is enabled with the request, but future renewal still depends on working validation. Confirm renewal settings and monitor the certificate actually served.
Check the result: Verify public HTTPS and test important pages. Check other hostnames separately before redirecting HTTPS traffic from them. Ask support about additional coverage; advanced Virtualmin SSL controls depend on your permissions. Virtualmin certificate guide
Common problems: A missing button can mean incomplete DNS, inactive or overdue hosting, a queued request, or the cooldown. Fix the displayed cause before retrying. Request certificate again may appear after issuance; it is not needed routinely when renewal works. A failed certificate request does not require another hosting purchase.
Related: SSL request and renewal failures, Certificate coverage, Mixed content.


Leave a Reply