Installing an SSL certificate on your hosting activates the HTTPS protocol, which encrypts the connection between your website and your visitors. Since 2018, Google Chrome has displayed a "Not Secure" warning on sites without SSL — enough to drive users away and hurt your search rankings.
The good news: most hosting plans include a free SSL certificate through Let's Encrypt, and you can activate it in under 5 minutes from your control panel.
Why Do You Need an SSL Certificate?
An SSL certificate (technically TLS today) does three essential things:
- Encrypts data in transit between the visitor's browser and your server, protecting passwords, card details, and form submissions.
- Authenticates your identity: proves the site is yours and not a malicious copy.
- Improves SEO: Google has used HTTPS as a ranking signal since 2014.
Types of SSL Certificates
| Type | Validation | Best for | Cost |
|---|---|---|---|
| DV (Domain Validation) | Domain only | Blogs, informational sites | Free (Let's Encrypt) |
| OV (Organization Validation) | Verified company | Businesses with corporate presence | ~$50–$200/yr |
| EV (Extended Validation) | Full legal identity | Banks, high-volume e-commerce | ~$150–$500/yr |
| Wildcard | DV/OV for *.domain.com | Multiple subdomains | Free or paid |
For most small and mid-sized business websites, a free DV certificate from Let's Encrypt is more than enough.
Install Free SSL with Let's Encrypt on cPanel
cPanel is the most widely used control panel in shared hosting. Here are the exact steps:
- Log in to your cPanel (e.g.,
yourdomain.com/cpanel). - Under the Security section, find SSL/TLS or Let's Encrypt SSL.
- Click Manage SSL for your site or the Let's Encrypt shortcut.
- Select the domain (and www) for which you want the certificate.
- Click Install Certificate or Issue.
- Wait 30 seconds to 2 minutes. cPanel will generate, validate, and install the certificate automatically.
If your provider uses cPanel's AutoSSL extension (most do), the certificate renews itself every 90 days — no action required on your part.
Don't See Let's Encrypt in Your cPanel?
Some providers offer SSL via SSL/TLS → Certificates. If your panel shows no free SSL option, contact your hosting support — nearly all current plans include it.
Install SSL on Plesk
Plesk is the most popular alternative panel, commonly used in Windows hosting environments:
- Log in to Plesk → select your domain.
- Go to Websites & Domains → SSL/TLS Certificates.
- Click Get it free or the Let's Encrypt button.
- Check the option to include
wwwand enter a notification email. - Click Install. Plesk handles the rest automatically.
Installing a Paid SSL Certificate
If you purchased an OV or EV certificate from a Certificate Authority (Comodo, DigiCert, Sectigo, etc.), the process has one extra step:
- Generate a CSR (Certificate Signing Request) from your hosting panel → SSL/TLS → Generate CSR. Copy the resulting text block.
- Submit the CSR to your CA and complete the validation they require (email, phone call, documents).
- The CA will send you three files: the certificate (.crt), the CA bundle (.ca-bundle), and your private key (.key) (already on the server).
- In cPanel: SSL/TLS → Install and Manage SSL → Manage SSL Sites. Paste each file's contents into the corresponding field and save.
Verify the Certificate Was Installed
Visit your site at https://yourdomain.com and check for the padlock icon in the browser bar. For a detailed check, use SSL Labs — it gives you an A–F grade and flags weak configurations.
Force HTTPS: Redirect All HTTP Traffic
Installing the certificate isn't enough — you also need to redirect HTTP traffic to HTTPS so no one can access the insecure version of your site.
Option 1: From cPanel
In cPanel → Domains → toggle on Force HTTPS Redirect. That's it.
Option 2: Via .htaccess (Apache)
Add these lines to the .htaccess file in your site root:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
The 301 redirect tells Google the change is permanent, passing full SEO value from old URLs to the new HTTPS versions.
Option 3: From WordPress
If you're on WordPress, install the Really Simple SSL plugin — it detects your certificate and enables the redirect with one click, no manual .htaccess editing needed.
If you'd prefer an expert team to handle all of this for you, visit elenlace.com and explore hosting plans that include SSL, forced HTTPS, and Spanish-language technical support.
Common SSL Installation Issues
- Mixed Content errors: your site loads over HTTPS but has images or scripts with
http://URLs. Fix: find and replace old URLs in your database, or use a plugin like Better Search Replace in WordPress. - Certificate not renewing automatically: check that your DNS CAA record isn't blocking Let's Encrypt, and that the validation files are publicly accessible.
- "NET::ERR_CERT_COMMON_NAME_INVALID" error: the certificate doesn't cover the exact domain you're visiting (e.g., it covers
wwwbut not the root domain, or vice versa). Reinstall covering both variants. - Expired certificate: Let's Encrypt certs last 90 days and must be renewed. If AutoSSL is active, renewal is automatic. Otherwise, renew manually from the panel.
For more hosting and web security terms, browse our complete glossary.
Key Takeaways
- An SSL certificate enables HTTPS, encrypts user data, and improves your Google rankings.
- Let's Encrypt provides free SSL, valid for 90 days, with automatic renewal on cPanel and Plesk.
- For most websites, a free DV certificate is more than sufficient.
- Installing SSL is only step one — you must also redirect all HTTP traffic to HTTPS.
- Always verify the result with SSL Labs to catch weak configurations early.
- Mixed Content errors are the most common post-migration issue when moving to HTTPS.
Want to activate HTTPS on your site today without the hassle? Contact the experts at elenlace.com — we install and configure your SSL at no extra charge on our hosting plans.
FAQ
Is the free Let's Encrypt SSL certificate secure?
Yes. Let's Encrypt issues DV certificates recognized by all modern browsers. The encryption strength is identical to paid certificates — the difference lies in the level of identity validation, not the technical security.
Do I need to renew SSL every year?
Let's Encrypt certificates last 90 days but renew automatically if your hosting has AutoSSL (cPanel) or the Let's Encrypt module (Plesk) active. Paid certificates typically last 1–2 years and require manual renewal.
Does SSL affect my site's performance?
The impact is minimal on modern servers. TLS 1.3 is actually faster than older versions, and HTTP/2 (which requires HTTPS) speeds up parallel resource loading — more than offsetting any overhead.
Do I need SSL if my site doesn't have an online store?
Yes. Google and Chrome mark any site without HTTPS as "Not Secure," which creates distrust even for blogs or company presentation sites. HTTPS is also a confirmed Google ranking factor, so it's worth enabling regardless of site type.
Compare providers
Other providers and guides worth comparing: