An SSL/TLS certificate helps a browser verify the server's identity and establish an encrypted HTTPS connection. Choose coverage for the actual names visitors use, then decide whether a free domain-validated certificate or a paid product meets your requirements.
- List your hostnames, including the main domain,
www, and any application subdomains. A redirect still needs a valid certificate on its starting HTTPS hostname because the secure connection happens before the redirect. - Compare coverage. A certificate for one hostname does not automatically cover every related name. A wildcard such as
*.example.comcovers matching names one level below it, such asshop.example.com; it does not by itself coverexample.comora.shop.example.com. Verify the actual names included by the chosen product. - Consider DNS & SSL → Request Let’s Encrypt SSL in Control Center for the selected website domain. This action requests that domain only; do not assume it includes
www, wildcards, or mail hostnames. Let's Encrypt itself supports more certificate configurations through suitable tools, but issues DV rather than OV or EV certificates. Let's Encrypt FAQ - Consider the paid catalog when you need a product or validation type it specifically offers. Read its Provider, Validation, Coverage, price, and term. DV validates domain control; OV and EV involve additional organization checks. Paying for a certificate does not itself make an unsafe application secure.
- Check lifecycle requirements. A paid subscription term can differ from the validity of an individual issued certificate. Free certificates also require continuing validation and successful renewal. Assign someone to monitor the certificate's actual expiry.
- Confirm who will install and maintain it. Issuance, installation, website HTTPS settings, and a mail or control-panel service certificate are separate concerns.
Check the choice: You should be able to name every required hostname, the validation type, the owner of renewal checks, and where the certificate will be installed. The storefront currently supports selected single-domain and wildcard products; contact support for requirements outside those options.
Common problems: Do not assume a wildcard includes the bare domain, a paid term guarantees one long-lived certificate, or a certificate purchase moves your website. Read the product's stated coverage and inspect the issued certificate after installation.
Related: Let's Encrypt setup, Buy a paid certificate, HTTPS troubleshooting.


Leave a Reply