Our features site is undergoing a refresh! Be sure to explore the revamped site and discover our latest product roadmap launching here on Monday, March 18th.

Toggle: "Manage Service SSL Certificates" renew self-signed certificates automatically.

Jim Tricarico shared this idea 11 years ago
Completed

Submitting this on behalf of a customer:

Currently, when certificates managed by WHM (for dovecot, exim, cpanel, and ftp) are 30 days away from expiration, root sends an email to the webserver maintainer asking them to use the "Manage Service SSL Certificates" tool to deal with the issue.


I am one of many administrators for whom certificates are somewhat mysterious and for whom this simple request is time-consuming to understand and deal with each time it arises.


In the final analysis, lacking the money to purchase my own certificates, I rely on the WHM facility to create self-signed certificates. The thing is, this process should be easy to automate, but WHM does not do so.


WHM should give the administrator the option to supply their own certificate, but if a week goes by and no certificate is supplied, WHM should simply and automatically create a new set of signed certificates so that Cpanel and the other entities can continue to run successfully. This could be done silently, without bothering the administrator. Requiring so much administrator time to learn what to do for such an unimportant detail as certificate expiration makes little sense.

Best Answer
photo

The Manage Service SSL Certificates feature already behaves similar to this. When a CA-signed service SSL certificate expires a self-signed certificate is put in its place. If your server is not behaving according to this description, and is running the latest version of cPanel & WHM (as shown on http://httpupdate.cpanel.net), please open a support ticket with us (https://support.cpanel.net).

Replies (3)

photo
1

The Manage Service SSL Certificates feature already behaves similar to this. When a CA-signed service SSL certificate expires a self-signed certificate is put in its place. If your server is not behaving according to this description, and is running the latest version of cPanel & WHM (as shown on http://httpupdate.cpanel.net), please open a support ticket with us (https://support.cpanel.net).

photo
1

Kenneth,


Does a toggle exist for this functionality in the 11.40 release? If so, could you point me to it?


Thanks!

photo
1

Jim Tricarico wrote:

Kenneth,


Does a toggle exist for this functionality in the 11.40 release? If so, could you point me to it?


Thanks!

There is no toggle. Each night, during upcp, the existing Service SSL Certificates are examined for validity. Any that are within a 30 day expiration window are flagged, and sent to the server admin for action. Once the certificate expires, a self-signed one is put in place. If this is not happening on your server I highly recommend opening a support ticket with our staff to investigate.

Replies have been locked on this page!