Control Center shows the result of its certificate request, while the live website presents the certificate visitors receive. Compare both when troubleshooting. A previous successful request does not prove later renewal succeeded, especially after DNS, proxy, or website-routing changes.
- Open Hosting services → Manage website → DNS & SSL → Get your hosting ready. Read Secure your site, copy any failure message, and check the selected domain. If the request is running, refresh in a few minutes instead of submitting again.
- Confirm the service is paid, active, and unexpired, and that the selected DNS method is confirmed. Keep my DNS provider is supported. With Lucid nameservers, delegation and hosting-record setup must both be complete. Hosting account creation itself does not wait for these DNS steps.
- Inspect the publicly served certificate's hostname coverage and expiry. The dashboard's standard request includes only the selected domain. An error on
wwwor another hostname can mean missing coverage even when the main domain works. - Check authoritative A and AAAA records and HTTP reachability. An old IPv6 record, unavailable origin, blocked challenge path, or redirect loop can break web validation. DNS validation used by a separately configured wildcard certificate needs its own functioning automation. Let's Encrypt validation methods
- For a renewal failure, open the domain's permitted SSL settings in Virtualmin or ask support to inspect them. Confirm automatic renewal, requested names, and the latest result. Keep validation access working between renewal cycles.
- Correct the cause before another attempt. Dashboard requests have a ten-minute cooldown. If an issuer error gives a longer retry time or rate limit, follow it. Repeated requests do not clear that limit. Let's Encrypt rate limits
- Contact support if the action remains queued, server permission is missing, or the cause is unclear. Include domain, order/service reference, actual expiry, exact error, and recent changes. Never attach a private key.
Check the result: After recovery, confirm the public site presents the replacement with the expected name and new expiry. A proxy may present a separate certificate from the hosting origin; both need appropriate configuration.
Common problems: Request certificate again creates another request; it is not an expiry monitor or a substitute for repairing renewal. Do not remove a hostname from an advanced certificate configuration until you know its HTTPS service is no longer needed. Ask support about CAA or DNSSEC failures rather than making guessed record changes.
Related: Initial setup, HTTPS diagnosis, Paid certificate lifecycle.


Leave a Reply