Reseller playbook · Beginner · 0–20 minutes
How to install an SSL certificate — The Certificate Warning a Client's Customer Sees First
A lapsed certificate on a client site is not a technical event — it is a full-page browser warning shown to their customers with your hosting behind it.
Straight answer first
On these accounts free certificates issue and reissue themselves as soon as a domain points here, so across a client estate your actual job is the exceptions: the domain that does not resolve yet, the hostname nobody covered, and the client who has been sold a paid certificate they do not need.
Anything from nothing to twenty minutes, depending on which of those you are dealing with. The part worth systematising is noticing a failure before the client's customers do.
Written by the Hosting Seller staff · Checked 24 August 2026
Beginner
Skill assumed
5
Stages of exception handling
Free
Cover included
Tested
Tested on our reseller stack
Written for whoever gets the phone call when a browser shows a full-page warning on a client's shop. It assumes many domains and subdomains across several accounts.
Most of this is already handled. What follows is the list of situations where it is not, and what each one looks like from the client's side of the screen.
AutoSSL is the default; your job is the exceptions
Free certificates are issued and installed automatically once a domain resolves to the account, and they reissue themselves before expiry. For the large majority of client sites, installation is something that has already happened without anyone doing anything, and the SSL/TLS Status screen is where you confirm it.
That turns the work into exception handling. Read that screen per account and you get a list of every domain and subdomain with its certificate state, which is exactly the report you want when you are responsible for dozens of names rather than one.
The hostnames on the certificate, and what they reveal
A certificate covers the names it was issued for. Where a client reaches their site or panel by a hostname belonging to the machine rather than to their own domain, the certificate that answers will cover a name that is not theirs — and the browser will say so, in front of whoever is looking.
This is the same white-label discipline that applies to nameservers and mail: keep client-facing addresses on client-facing domains. Then the certificate matches, there is no warning, and nobody has to be told which company operates the server in order to explain a padlock.
When a client asks for a paid certificate
Sometimes the answer is yes. Wildcard coverage across many subdomains, or organisation validation because the client's own compliance people have asked for it, are real requirements and the paid tiers exist for them. Selling one is legitimate and straightforward.
Often the answer is no, and saying so builds more trust than the margin is worth. A domain-validated certificate bought because the site 'needs SSL' uses identical encryption to the free one already installed. What the paid tiers sell is deeper validation and wider coverage, not a better padlock.
Catching the failure before the client's customer does
Automatic renewal depends on the domain still resolving to the account that issued the certificate. When a client's marketing agency moves DNS without telling anyone, renewal stalls quietly and the expiry arrives weeks later as a browser warning on a live shop.
So watch the exceptions rather than the successes. Check the status screen across your accounts on a schedule, and treat any domain that has stopped resolving here as an urgent item, because it is a certificate that will lapse on a date already in the calendar.

What is already handled per client account
Free SSL is issued on every site you host for a client and reissues itself before it lapses, so the padlock is not something anybody has to diary.
Wildcard and organisation-validated certificates are on the shelf for the client whose compliance team genuinely requires one.
- Certificates issued the moment DNS points here
- One status screen per account, read as a report
- Client-facing names on client-facing domains
- Stalled renewals treated as the urgent case
Why Hosting Seller
On every plan, as standard
Exception handling, not installation
Assumes AutoSSL has already done the routine work and concentrates on the cases where it cannot.
A report you can read fast
Uses the status screen per account as an inventory of every domain and its certificate state.
The warning, from the client's side
Describes what a mismatched hostname looks like to somebody who is not technical.
An honest sales position
Separates the paid certificates a client genuinely needs from the ones they have been talked into.
Renewal failure explained
Names DNS moving away as the cause, which is what makes it foreseeable rather than bad luck.
Free on every client site
Certificates issue and reissue themselves on every account, with wildcard and EV available when needed.
First Steps
From choosing to live
- 1
Read the status screen per client account
It lists every domain and subdomain with its certificate state. Green is done; a warning names the exact hostname that still needs attention, which is the whole of your working list.
- 2
Chase DNS whenever issuance has failed
A certificate cannot be issued for a name that does not resolve to the account. Fix the pointing, allow a little time, and the system will pick it up by itself — the certificate follows the DNS, never the other way round.
- 3
Confirm both www and the bare domain are covered
It happens automatically here, and it is still worth checking on a client's commercial site. A certificate covering one form while visitors arrive at the other produces a warning that looks catastrophic and is only a mismatch.
- 4
Install a purchased certificate by hand when it is justified
Generate the CSR in the panel, give it to the certificate authority, then paste the issued certificate back under Install SSL. Five fields and five minutes — worth doing when the client's requirement is real.
- 5
Schedule the exception check across your accounts
Renewal only stalls quietly, never loudly. A recurring look at the status screens catches a domain that has been moved away long before its certificate reaches its expiry date.
In the Box
Packed with every plan
- Free SSL on every site you host for a client
- Certificates reissued before they lapse, automatically
- Wildcard and EV certificates on the shelf when needed
- A cPanel of their own for every client, WHM for you
- Private nameservers under your own brand
- Daily backups across every client account
- Site migration done for you by our staff, at no charge
- One-click installs for WordPress and 400+ other applications
- cPanel, the panel the rest of the trade already knows
- Real people answer, for you and for them
Across the Counter
Things people ask us all the time
AutoSSL has failed on one client domain — where do I look first?
At DNS. Issuance requires the name to resolve to the account, so a domain still pointing at a previous host, or one whose zone is answered by an agency elsewhere, cannot be covered. Correct the pointing and the system retries on its own.
Should I resell paid certificates or talk clients out of them?
Both, depending on the requirement. Wildcard coverage and organisation validation are genuine needs and worth selling. A domain-validated certificate bought because a site 'needs SSL' duplicates the free one already installed, and saying so is worth more than the margin.
A client moved their DNS and the certificate expired — how do I prevent the next one?
Check the certificate status screens across your accounts on a schedule, and treat any client domain that has stopped resolving here as urgent. Renewal failure is always silent, so the only reliable detection is a recurring look rather than an alert.
Will you move an existing client site across at no charge?
Yes. Open a ticket with the current host's login details and the lot comes over — files, databases, mailboxes and configuration. You check the copy before DNS changes hands, and the old site keeps serving until it does, so the client never sees a gap.
Read next
AI Website Builder
Describe the site and the AI builder drafts it on real hosting — useful for a fast client turnaround.
WordPress Hosting
WordPress hosting for the client sites you look after — LiteSpeed, staging and daily backups.
Moving your site to another host? Start with this checklist.
A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.
Never explain a padlock again.
Free SSL on every client site, reissued before it lapses, with wildcard and EV on the shelf when asked.
See AI Website Builder plans