+254725682556 +254725052660 info@ziprof.co.ke
Client Area

SSL

How to Renew Your SSL Certificate Before It Expires

An SSL certificate is only valid for a set period, usually 90 days for a free certificate or up to a year for a paid one. When it expires, visitors to your website will see a "Not Secure" or "Your connection is not private" warning in their browser, even if nothing else about your site has changed. Renewing it before that happens keeps your website trusted and your checkout, contact forms, and login pages working the way visitors expect.

How to check when your SSL certificate expires

Before renewing, confirm the actual expiry date so you know whether action is needed right away.

  1. Visit your website in a browser and click the padlock icon next to the address bar.
  2. Select Connection is secure, then Certificate is valid (labels vary slightly by browser).
  3. Look for the Valid to or Expires on date.

You can also check this directly from your hosting control panel, covered below.

Renewing a free SSL certificate

Most free certificates issued through your hosting account are set to renew automatically. If you're seeing an expiry warning anyway, it usually means the automatic renewal failed, often because a DNS record was changed or the domain briefly stopped pointing to your hosting server.

In cPanel

  1. Log in to cPanel and open SSL/TLS Status under the Security section.
  2. Select the domain and click Run AutoSSL to force an immediate renewal check.
  3. Wait a few minutes, then refresh the page to confirm the new expiry date shows.

If AutoSSL fails repeatedly, check that your domain's A record points to your current hosting server's IP address, since AutoSSL cannot issue a certificate for a domain pointing elsewhere.

In DirectAdmin

  1. Log in to DirectAdmin and open SSL Certificates under the Account Manager section.
  2. Choose Free & automatic certificate from Let's Encrypt and click Save to trigger a fresh issuance.
  3. Confirm the certificate section now shows an updated expiry date.

Renewing a paid SSL certificate

Paid certificates do not renew on their own. You'll need to generate a new certificate order before the current one expires.

In cPanel

  1. Generate a new CSR (Certificate Signing Request) from SSL/TLS > Generate, view, upload, or delete SSL certificate signing requests, unless your certificate provider allows you to reuse the existing one.
  2. Submit the CSR to renew the order with your certificate provider and complete any domain validation steps they require.
  3. Once issued, go to SSL/TLS > Install and Manage SSL for your site (HTTPS) and paste in the new certificate to replace the old one.

In DirectAdmin

  1. Open SSL Certificates and generate a new CSR if your provider requires one for the renewal.
  2. Complete the renewal and validation process with your certificate provider.
  3. Select Paste a pre-generated certificate and key, paste in the newly issued certificate, and click Save.
Renew a paid certificate at least a week before it expires. Certificate validation and installation can take longer than expected, and a lapsed certificate means your website shows security warnings until the new one is fully installed.

If you're moving from a paid certificate to a free one instead of renewing, see How to Install a Free SSL Certificate with AutoSSL for the full setup steps.