Skip to main content
HostingSeller
Shop plans

Reseller playbook · Beginner · 0–20 minutes

How to install an SSL certificate — The Certificate Warning a Client's Customer Sees First

A lapsed certificate on a client site is not a technical event — it is a full-page browser warning shown to their customers with your hosting behind it.

Straight answer first

On these accounts free certificates issue and reissue themselves as soon as a domain points here, so across a client estate your actual job is the exceptions: the domain that does not resolve yet, the hostname nobody covered, and the client who has been sold a paid certificate they do not need.

Anything from nothing to twenty minutes, depending on which of those you are dealing with. The part worth systematising is noticing a failure before the client's customers do.

Written by the Hosting Seller staff · Checked 24 August 2026

Beginner

Skill assumed

5

Stages of exception handling

Free

Cover included

Tested

Tested on our reseller stack

Written for whoever gets the phone call when a browser shows a full-page warning on a client's shop. It assumes many domains and subdomains across several accounts.

Most of this is already handled. What follows is the list of situations where it is not, and what each one looks like from the client's side of the screen.

AutoSSL is the default; your job is the exceptions

Free certificates are issued and installed automatically once a domain resolves to the account, and they reissue themselves before expiry. For the large majority of client sites, installation is something that has already happened without anyone doing anything, and the SSL/TLS Status screen is where you confirm it.

That turns the work into exception handling. Read that screen per account and you get a list of every domain and subdomain with its certificate state, which is exactly the report you want when you are responsible for dozens of names rather than one.

The hostnames on the certificate, and what they reveal

A certificate covers the names it was issued for. Where a client reaches their site or panel by a hostname belonging to the machine rather than to their own domain, the certificate that answers will cover a name that is not theirs — and the browser will say so, in front of whoever is looking.

This is the same white-label discipline that applies to nameservers and mail: keep client-facing addresses on client-facing domains. Then the certificate matches, there is no warning, and nobody has to be told which company operates the server in order to explain a padlock.

When a client asks for a paid certificate

Sometimes the answer is yes. Wildcard coverage across many subdomains, or organisation validation because the client's own compliance people have asked for it, are real requirements and the paid tiers exist for them. Selling one is legitimate and straightforward.

Often the answer is no, and saying so builds more trust than the margin is worth. A domain-validated certificate bought because the site 'needs SSL' uses identical encryption to the free one already installed. What the paid tiers sell is deeper validation and wider coverage, not a better padlock.

Catching the failure before the client's customer does

Automatic renewal depends on the domain still resolving to the account that issued the certificate. When a client's marketing agency moves DNS without telling anyone, renewal stalls quietly and the expiry arrives weeks later as a browser warning on a live shop.

So watch the exceptions rather than the successes. Check the status screen across your accounts on a schedule, and treat any domain that has stopped resolving here as an urgent item, because it is a certificate that will lapse on a date already in the calendar.

A padlock on a laptop screen standing in for a free SSL certificate

What is already handled per client account

Free SSL is issued on every site you host for a client and reissues itself before it lapses, so the padlock is not something anybody has to diary.

Wildcard and organisation-validated certificates are on the shelf for the client whose compliance team genuinely requires one.

  • Certificates issued the moment DNS points here
  • One status screen per account, read as a report
  • Client-facing names on client-facing domains
  • Stalled renewals treated as the urgent case

Why Hosting Seller

On every plan, as standard

Exception handling, not installation

Assumes AutoSSL has already done the routine work and concentrates on the cases where it cannot.

A report you can read fast

Uses the status screen per account as an inventory of every domain and its certificate state.

The warning, from the client's side

Describes what a mismatched hostname looks like to somebody who is not technical.

An honest sales position

Separates the paid certificates a client genuinely needs from the ones they have been talked into.

Renewal failure explained

Names DNS moving away as the cause, which is what makes it foreseeable rather than bad luck.

Free on every client site

Certificates issue and reissue themselves on every account, with wildcard and EV available when needed.

First Steps

From choosing to live

  1. 1

    Read the status screen per client account

    It lists every domain and subdomain with its certificate state. Green is done; a warning names the exact hostname that still needs attention, which is the whole of your working list.

  2. 2

    Chase DNS whenever issuance has failed

    A certificate cannot be issued for a name that does not resolve to the account. Fix the pointing, allow a little time, and the system will pick it up by itself — the certificate follows the DNS, never the other way round.

  3. 3

    Confirm both www and the bare domain are covered

    It happens automatically here, and it is still worth checking on a client's commercial site. A certificate covering one form while visitors arrive at the other produces a warning that looks catastrophic and is only a mismatch.

  4. 4

    Install a purchased certificate by hand when it is justified

    Generate the CSR in the panel, give it to the certificate authority, then paste the issued certificate back under Install SSL. Five fields and five minutes — worth doing when the client's requirement is real.

  5. 5

    Schedule the exception check across your accounts

    Renewal only stalls quietly, never loudly. A recurring look at the status screens catches a domain that has been moved away long before its certificate reaches its expiry date.

In the Box

Packed with every plan

  • Free SSL on every site you host for a client
  • Certificates reissued before they lapse, automatically
  • Wildcard and EV certificates on the shelf when needed
  • A cPanel of their own for every client, WHM for you
  • Private nameservers under your own brand
  • Daily backups across every client account
  • Site migration done for you by our staff, at no charge
  • One-click installs for WordPress and 400+ other applications
  • cPanel, the panel the rest of the trade already knows
  • Real people answer, for you and for them

Across the Counter

Things people ask us all the time

AutoSSL has failed on one client domain — where do I look first?

At DNS. Issuance requires the name to resolve to the account, so a domain still pointing at a previous host, or one whose zone is answered by an agency elsewhere, cannot be covered. Correct the pointing and the system retries on its own.

Should I resell paid certificates or talk clients out of them?

Both, depending on the requirement. Wildcard coverage and organisation validation are genuine needs and worth selling. A domain-validated certificate bought because a site 'needs SSL' duplicates the free one already installed, and saying so is worth more than the margin.

A client moved their DNS and the certificate expired — how do I prevent the next one?

Check the certificate status screens across your accounts on a schedule, and treat any client domain that has stopped resolving here as urgent. Renewal failure is always silent, so the only reliable detection is a recurring look rather than an alert.

Will you move an existing client site across at no charge?

Yes. Open a ticket with the current host's login details and the lot comes over — files, databases, mailboxes and configuration. You check the copy before DNS changes hands, and the old site keeps serving until it does, so the client never sees a gap.

Read next

  • AI Website Builder

    Describe the site and the AI builder drafts it on real hosting — useful for a fast client turnaround.

  • WordPress Hosting

    WordPress hosting for the client sites you look after — LiteSpeed, staging and daily backups.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Never explain a padlock again.

Free SSL on every client site, reissued before it lapses, with wildcard and EV on the shelf when asked.

See AI Website Builder plans