Skip to content
GiddyHost Nigeria
Hosting

How to Install SSL Through cPanel on Your Website

Learn how to install SSL through cPanel, activate HTTPS, fix common certificate errors and protect your Nigerian business website with confidence today.

GiddyHost Team

6 min read

How to Install SSL Through cPanel on Your Website
On this page6
  1. 1.Before You Install SSL Through cPanel
  2. 2.Option One: Activate Free SSL in cPanel
  3. 3.How to Install SSL Through cPanel Manually
  4. 4.Make HTTPS the Default Version of Your Website
  5. 5.Fix Common SSL Problems in cPanel
  6. 6.Keep the Certificate Working for Your Customers

A browser warning can stop a potential customer before they see your products, portfolio or contact details. When you install SSL through cPanel, your website moves from HTTP to HTTPS, protecting information submitted through forms, login pages and checkout screens while showing visitors that your business takes security seriously.

For Nigerian businesses accepting enquiries, payments or customer details online, SSL is no longer an optional technical extra. It is a practical requirement for trust, search visibility and day-to-day website security. The good news is that cPanel makes the process manageable, whether your hosting plan includes a free certificate or you have bought one separately.

Before You Install SSL Through cPanel

Start by checking that your domain points to the correct hosting account. An SSL certificate can only be issued or installed when the domain resolves to the server where the website is hosted. If you recently changed nameservers, transferred your domain or updated DNS records, allow time for those changes to propagate before trying again.

You also need to know which type of certificate you are working with. Many modern hosting accounts include AutoSSL or a similar service that automatically issues and renews a domain-validated certificate. This is the simplest route. In that case, you may not need to upload any certificate files at all.

A manually purchased certificate is different. Your certificate provider will normally send a certificate file, often called a CRT, plus one or more intermediate certificates known as a CA bundle. You must also have the private key created when you generated the Certificate Signing Request, or CSR. Without the matching private key, the certificate cannot be installed.

Before making changes, confirm that the domain and any version you need are covered. For example, a certificate for example.ng may not automatically cover www.example.ng unless both names are included. A wildcard certificate can cover subdomains such as shop.example.ng, but it does not replace a certificate for entirely different domain names.

Option One: Activate Free SSL in cPanel

If your hosting package provides free SSL, first log in to cPanel from your hosting client area. Look for the SSL/TLS Status icon in the Security section. The page displays domains in the account and shows whether each domain has a valid certificate.

Select the relevant domain, including the www version if it appears separately, then choose Run AutoSSL. cPanel will attempt domain validation and install a certificate automatically. Depending on your server and DNS setup, this can take a few minutes.

Once the process has completed, return to SSL/TLS Status and check for a green or positive status beside the domain. Open your website using https:// before the domain. If the browser displays a padlock and no certificate warning, the certificate is active.

On eligible GiddyHost hosting packages, free SSL is designed to reduce the cost and effort of securing a new website. Still, automatic issuance depends on correct DNS. If the domain points elsewhere, has conflicting records or sits behind an incorrectly configured proxy, AutoSSL may fail even when the hosting account is working normally.

How to Install SSL Through cPanel Manually

Use the manual installation route when you have received certificate files from a certificate authority or reseller. In cPanel, open SSL/TLS, then select Manage SSL sites under the section for installing and managing SSL certificates.

Choose the domain from the dropdown list. cPanel may automatically fill the private key field if it finds the matching key in your account. Paste or upload the certificate into the Certificate: (CRT) field. Then paste the intermediate certificate chain into the Certificate Authority Bundle: (CABUNDLE) field, if your provider supplied one.

Check every field carefully before selecting Install Certificate. A missing CA bundle can cause some devices or browsers to show a trust error, even though the main certificate appears to be installed. Similarly, using a private key that belongs to another CSR will trigger an error because the key and certificate do not match.

After installation, visit both https://yourdomain and https://www.yourdomain, where relevant. Test the pages that matter most: your contact form, WordPress login area, online shop and any page collecting customer information. A certificate can be installed correctly while parts of the website still load insecure content.

Generating a CSR when you need one

If your provider asks for a CSR before issuing the certificate, go to SSL/TLS and select Generate, view or delete SSL certificate signing requests. Enter the domain name exactly as required. For a single-domain certificate, this is usually your main domain; for a wildcard certificate, it usually begins with an asterisk, such as *.example.ng.

Complete the organisation details accurately, then generate the CSR. Copy the entire CSR block, including the opening and closing lines, and submit it to your certificate provider. Keep the private key in cPanel untouched. Once the certificate is issued, return to Manage SSL sites and complete the manual installation.

Make HTTPS the Default Version of Your Website

Installing a certificate does not always redirect visitors from HTTP to HTTPS. Without a redirect, two versions of the same page may remain accessible, and a visitor following an old link could still land on the insecure address.

Many cPanel accounts include a Domains tool with a Force HTTPS Redirect option. Enable it for the correct domain, then test the site in a private browser window. This is often the easiest choice for a standard website.

WordPress users should also check the WordPress Address and Site Address settings. Both should use https:// after the certificate is active. If you change these addresses too early, before SSL works, you can make the site difficult to access. Make the change only after testing the secure version successfully.

Some websites use redirects in an .htaccess file, a caching plugin or an application-level setting instead. That can be appropriate for advanced setups, but use one clear redirect method rather than stacking several. Competing rules can create redirect loops, where the browser repeatedly moves between URLs and never loads the page.

Fix Common SSL Problems in cPanel

The most common problem is a certificate mismatch. This happens when the certificate covers one name but the visitor opens another, such as www.example.ng instead of example.ng. Check the certificate’s listed domain names and install a certificate that includes every version you plan to use.

Another common issue is mixed content. Your main page may load over HTTPS, but images, fonts, scripts or embedded resources may still use HTTP. Browsers may show a warning or remove the padlock. Update old hard-coded HTTP URLs in your website settings, theme files, page builder content and database. For WordPress, a trusted search-and-replace process is usually safer than editing database entries manually.

If AutoSSL cannot validate the domain, inspect your DNS records. The A record should point to the correct server, and the domain should not be redirected to a different service during validation. Temporary maintenance pages, restrictive firewall rules and misconfigured CDN settings can also interfere with validation.

An expired certificate deserves prompt attention. Free certificates often renew automatically, but renewal can fail if DNS changes or validation requirements are no longer met. Check SSL/TLS Status before the expiry date rather than waiting for visitors to report a warning. For a paid certificate, set a reminder well ahead of renewal and keep your provider’s renewal emails accessible.

Finally, clear browser, website and CDN caches after enabling HTTPS. A cached redirect or old asset can make a resolved problem look as if it is still active. Test from a mobile network as well as your usual office connection for a more realistic visitor view.

Keep the Certificate Working for Your Customers

SSL is not a one-off tick box. Keep your domain registration current, avoid unnecessary DNS changes and review the SSL status whenever you move hosting, launch a subdomain or change website platforms. If your business uses professional email, payment pages or client portals, these checks are especially worthwhile because trust is directly tied to every interaction.

A valid HTTPS connection gives customers a quieter, more confident experience: no warning screens, no uncertainty at checkout and no reason to question whether their information is safe. Set it up carefully once, then make certificate monitoring part of your regular website housekeeping.

Found this useful? Share it.

Written by

GiddyHost Team

Practical guides on hosting, domains, email and website security from the team behind GiddyHost Nigeria. Questions about this article? Talk to our 24/7 support team.

Keep reading

More on Hosting.

All Hosting articles

Ready to launch your website?

Get online today with free SSL, free migration and a 30-day money-back guarantee.