
Let's Encrypt is a free Certificate Authority that issues SSL certificates to any domain at no cost. However, these certificates expire every 90 days. If renewal fails, your website will display scary security warnings to visitors, damaging trust and SEO rankings instantly. This guide walks you through setting up automatic SSL renewal on DirectAdmin Hosting so your certificate never expires again.
Why Does Let's Encrypt Expire So Frequently?
Let's Encrypt intentionally keeps certificate lifetimes short at 90 days. This design encourages automation and reduces the blast radius if a private key is ever compromised. Common reasons certificates still expire despite auto-renewal:
- AutoSSL was never correctly configured at the start
- The Cron Job running Certbot was deleted or stopped
- DNS validation fails due to incorrect DNS records
- Moving to a new host without reconfiguring AutoSSL
- The server was unreachable during the renewal window
Method 1 — Use AutoSSL in DirectAdmin (Recommended)
DirectAdmin includes a built-in AutoSSL feature that integrates directly with Let's Encrypt. This is the easiest and most reliable approach for most shared hosting users.
Enabling AutoSSL
- Log in to your DirectAdmin panel
- Navigate to Advanced Features → SSL Certificates
- Select your domain and click Free & automatic certificate from Let's Encrypt
- Check Enable SSL and Force SSL with https redirect
- Click Save
Once AutoSSL is enabled, DirectAdmin will automatically renew the certificate 30 days before expiry using the system's built-in Cron Job. No additional configuration is needed.
Important: AutoSSL requires that your domain's DNS A record points to the server IP before running. If you use Cloudflare with Proxy enabled (orange cloud), temporarily switch to DNS Only (grey cloud) before renewal, then re-enable Proxy afterward.
Method 2 — Set Up a Certbot Cron Job
If you have Shell Access on your hosting account or prefer manual control, you can configure a Cron Job to run Certbot directly.
Adding the Cron Job in DirectAdmin
- Go to Advanced Features → Cron Jobs
- Set the schedule to
0 3 * * 1(every Monday at 03:00 AM) - Enter the command:
/usr/local/bin/certbot renew --quiet --post-hook "systemctl reload apache2" - Click Add
/usr/local/bin/certbot renew --quiet --post-hook "systemctl reload apache2"
The --quiet flag suppresses email notifications on every run. The --post-hook reloads Apache after a successful renewal so the new certificate takes effect immediately.
Checking SSL Certificate Status
After configuration, verify that renewal is working using these methods:
Via DirectAdmin Panel
Go to SSL Certificates and check the expiry date displayed. After a successful renewal, you should see a new date 90 days out.
Via OpenSSL Command Line
echo | openssl s_client -connect yourdomain.com:443 2>/dev/null | openssl x509 -noout -dates
The output shows notAfter= — your certificate expiry date.
Using an Online Tool
Use the AsiaGB SSL Server Test to check your certificate status instantly from any browser.
Troubleshooting AutoSSL Failures
If AutoSSL fails, check these issues in order:
- DNS propagation — Confirm the A record points to the correct server IP
- Port 80 open — Let's Encrypt uses HTTP-01 Challenge on port 80
- Cloudflare Proxy — Temporarily disable the orange cloud and retry
- Rate limits — Let's Encrypt limits 5 certificates per domain per week; too many failed attempts cause a temporary block
- Check Error Logs — Go to DirectAdmin → Error Log for AutoSSL messages
Set Up Expiry Alerts
Even with AutoSSL configured, it is good practice to set up external monitoring. Services like Uptime Robot and StatusCake offer free SSL expiry monitoring. Configure alerts at 30, 14, and 7 days before expiry to give yourself time to investigate if AutoSSL stops working unexpectedly.
Let's Encrypt vs. Paid SSL Certificates — Which Should You Choose?
Many site owners wonder whether to continue using free Let's Encrypt or upgrade to a paid SSL certificate. The right choice depends on your website type, audience, and business requirements. Use the table below to compare the two options.
| Feature | Let's Encrypt (Free) | Paid SSL (DV / OV / EV) |
|---|---|---|
| Cost | Free | From 1,000 THB/year |
| Certificate lifetime | 90 days (requires frequent renewal) | 1–2 years depending on plan |
| Wildcard Subdomain | Supported (DNS Challenge) | Supported (Wildcard SSL) |
| Organization Validation (OV/EV) | Not available (DV only) | Available for OV and EV |
| Warranty coverage | None | Included (varies by plan) |
| Best suited for | Blogs, personal sites, SMBs | E-commerce, banks, enterprises |
For general websites that do not process payments directly, Let's Encrypt is fully sufficient and cost-effective. For large e-commerce platforms or businesses that need to display their organization name in the certificate (OV/EV), a paid SSL is the better investment. AsiaGB offers both free Let's Encrypt AutoSSL and paid SSL certificates to suit every requirement.
Managing Let's Encrypt on Wildcard Subdomains
If your site uses multiple subdomains — such as shop.yourdomain.com, api.yourdomain.com, and mail.yourdomain.com — you can issue a single Wildcard Certificate that covers all of them. However, this requires the DNS-01 Challenge method instead of the standard HTTP-01 Challenge.
Issuing a Wildcard Certificate with Certbot
certbot certonly \
--manual \
--preferred-challenges=dns \
-d "*.yourdomain.com" \
-d "yourdomain.com"
Certbot will ask you to add a DNS TXT record named _acme-challenge.yourdomain.com to your DNS zone. Because this value changes with each renewal, Wildcard certificates typically require manual renewal or a DNS provider that supports a Certbot DNS plugin — such as Cloudflare or Route53.
Wildcard Certificate Limitations in DirectAdmin AutoSSL
- DirectAdmin AutoSSL supports Wildcard only on newer versions using ACME v2
- Check with your hosting provider if you are on shared hosting
- Wildcard covers only one level of subdomains —
*.yourdomain.comdoes not coversub.shop.yourdomain.com
Tip: If you manage many subdomains, consider upgrading to a paid Wildcard SSL certificate from AsiaGB. It renews annually with no DNS challenge required every 90 days, simplifying certificate management significantly.
Re-Issuing Let's Encrypt After Hosting Migration
When migrating to a new hosting server, your Let's Encrypt certificate cannot be transferred along with your website files. The certificate is tied to the private key stored on the old server and must be re-issued on the new one.
Recommended Steps During a Hosting Migration
- Set up and test your website on the new server first (via the Hosts file or a staging URL)
- Update the domain's A record to the new server IP and wait for DNS propagation to complete
- Enable AutoSSL in the new server's DirectAdmin panel to issue a fresh certificate
- Verify that the new certificate was issued successfully before decommissioning the old server
- Confirm that AutoSSL or a Cron Job is fully configured on the new server
All AsiaGB Hosting plans include AutoSSL support on DirectAdmin, making this process straightforward — just a few clicks and your SSL is live on the new server. Our 99% uptime guarantee and Thai-language support team are available 24 hours a day to assist with any migration questions.
Hosting with Free Let's Encrypt AutoSSL
AsiaGB SSD Hosting includes free Let's Encrypt AutoSSL on every plan. Starting from just 500 THB/year with DirectAdmin and 99% Uptime guarantee.
View Hosting Plans