An issued certificate must be installed with the private key used for its CSR. Downloading the certificate from your order does not automatically configure a separate hosting panel, proxy, or mail service. Keep the existing working configuration available until the replacement has been verified.
The paid certificate's download remains in My Account → Orders. Control Center's DNS & SSL section does not import or install this paid certificate for you.
- Sign in to the website account that owns the purchase. Open My Account → Orders, view the SSL order, and select Refresh status if validation has recently finished.
- Wait for the order to show Certificate issued. Choose Download certificate and chain when available. Download is withheld while issuance, domain coverage, or the CSR public-key match remains unverified.
- Save the downloaded PEM content in private working storage. Identify the server certificate and any intermediate certificates in the chain. The download does not contain your private key; retrieve that from the server or secure storage where the CSR was generated.
- Select the domain in Virtualmin and open Manage Virtual Server → Setup SSL Certificate → Update Certificate and Key. Supply the certificate and its matching private key as the panel requires, retaining an already configured matching key when supported. Install the provided intermediate chain in the panel's CA/intermediate certificate controls. Virtualmin installation guide
- Read any validation result before saving. If the key does not match, stop and locate the correct key or arrange a reissue. Editing certificate text cannot make an unrelated key match.
- Visit each covered hostname using HTTPS. Once the certificate works, review HTTPS redirects and the application's secure URLs.
Check the result: Inspect the publicly served certificate's hostname coverage, issuer, expiry, and trust status. If a CDN or proxy handles public HTTPS, check its certificate separately from the hosting origin. Test a second browser or device to help catch a missing intermediate chain.
Common problems: A pending verification message can persist after the registrar reports issuance; ask support if refreshing does not resolve it. A missing installation menu requires support or the administrator of the destination hosting service. Installing the website certificate does not automatically replace a shared email-server or control-panel certificate.
Related: Create the CSR, Reissue or expiry, HTTPS troubleshooting.


Leave a Reply