SSL

SSL Auto-Renewal on DirectAdmin
How to Prevent Certificate Expiry

📅 October 6, 2026 ⏱ ~8 min read 🔐 SSL & Security
SSL Certificate Auto-Renewal on DirectAdmin

📋 Table of Contents

  1. Why SSL Certificates Expire Unexpectedly
  2. How AutoSSL Works on DirectAdmin
  3. Enabling AutoSSL on DirectAdmin
  4. First-Time Let's Encrypt Setup
  5. Checking Renewal Status
  6. Common Problems and Solutions
  7. Renewing Paid SSL Certificates
  8. Let's Encrypt vs Paid SSL Comparison
  9. SSL Management Best Practices
  10. Frequently Asked Questions

An expired SSL certificate is one of the most common problems website owners face. When an SSL certificate expires, browsers display "Your connection is not private," immediately driving visitors away. This guide covers how to set up automatic SSL renewal on DirectAdmin for both Let's Encrypt and Paid SSL, so you never have to worry about certificate expiry again.

1. Why SSL Certificates Expire Unexpectedly

SSL certificates have a limited lifespan — Let's Encrypt certificates last only 90 days, while Paid SSL certificates last 1 year or more. Without an automatic renewal system, website owners must remember expiry dates and renew manually, which is easy to forget.

⚠️ Impact of expired SSL: Browser shows "Your connection is not private" → Visitors panic and leave → Traffic drops sharply → Negative impact on SEO rankings

2. How AutoSSL Works on DirectAdmin

DirectAdmin includes an AutoSSL feature that integrates with Let's Encrypt via the ACME protocol. The process works as follows:

1 Certificate scan every 12 hours to find certificates expiring within 30 days

2 Renewal request sent to Let's Encrypt CA via HTTP-01 or DNS-01 challenge

3 Domain ownership verification by Let's Encrypt accessing a file in /.well-known/acme-challenge/

4 New certificate saved to DirectAdmin and Apache/Nginx automatically reloaded

3. Enabling AutoSSL on DirectAdmin

Enabling AutoSSL on DirectAdmin Hosting can be done through the DirectAdmin User Panel:

1 Log in to DirectAdmin User Panel (usually port 2222)

2 Click SSL Certificates under "Your Account"

3 Select "Let's Encrypt" option at the bottom

4 Check the "AutoSSL" or "Auto-renew" checkbox

5 Click Save — the system will issue a new certificate and configure auto-renewal

💡 Tip: If your site uses both www and non-www, ensure the certificate covers both by including domain.com and www.domain.com in the domain field.

4. First-Time Let's Encrypt Setup

If you haven't installed SSL on DirectAdmin before, follow these steps first:

  1. Log in to DirectAdmin → SSL Certificates
  2. Select Let's Encrypt (not "Paste a pre-generated certificate")
  3. Verify the domain has a correct DNS A record pointing to the server's IP
  4. Choose the domains and subdomains to cover
  5. Click Save — wait 1-2 minutes for the certificate to be issued
  6. Enable Force HTTPS Redirect via DirectAdmin → htaccess Manager
❗ Important: Port 80 must be open to internet traffic for Let's Encrypt's HTTP-01 challenge to work. If your firewall blocks port 80, certificate issuance will fail.

5. Checking Renewal Status

How to verify your SSL will renew successfully:

Via DirectAdmin

Via Browser

Via Command Line (for VPS)

openssl s_client -connect domain.com:443 -servername domain.com 2>/dev/null \
  | openssl x509 -noout -dates

6. Common Problems and Solutions

ProblemCauseSolution
SSL expires despite AutoSSL enabledPort 80 blocked or DNS incorrectCheck firewall rules and DNS records
"Too Many Requests" from Let's EncryptMore than 5 certificate requests per domain per weekWait 1 week then retry
Certificate issued but browser still shows "not secure"Mixed content (images/scripts using HTTP)Update all URLs to HTTPS
Wildcard domain not coveredCertificate issued without wildcardRe-issue certificate with *.domain.com
AutoSSL not running automaticallyDirectAdmin cron job not workingContact hosting provider to check

For Paid SSL certificates (RapidSSL, GeoTrust, Symantec), renewal must be done through the SSL provider:

1 Purchase a new certificate at least 30 days before expiry at billing.in.th

2 Generate a CSR via DirectAdmin → SSL Certificates → "Paste a pre-generated certificate" → Generate CSR

3 Submit CSR to CA for domain validation

4 Receive certificate files via email and upload to DirectAdmin

5 Verify that the browser shows 🔒 correctly

💡 Tip: AsiaGB Hosting customers can contact Support to have Paid SSL installed for them — no need to do it yourself.

8. Let's Encrypt vs Paid SSL Comparison

FeatureLet's EncryptPaid SSL (DV)Paid SSL (OV/EV)
PriceFreeFrom 1,000 THB/yearFrom 4,000 THB/year
Validity90 days1 year1 year
RenewalAutomatic (AutoSSL)Manual purchase requiredManual purchase required
Shows organization nameNoNoYes (OV/EV)
WarrantyNoneUp to $10,000+Up to $1.5M
Best forBlogs, personal sitesSmall businessesE-commerce, finance

9. SSL Management Best Practices

📊 Key Statistic: 90% of unintended SSL expirations occur because website owners forgot to manually renew Paid SSL — using Let's Encrypt with AutoSSL eliminates this problem entirely for most websites.

10. Summary

Setting up automatic SSL renewal on DirectAdmin is straightforward. Simply enable AutoSSL with Let's Encrypt through the SSL Certificates section in DirectAdmin Panel, and the system will handle everything automatically. For websites requiring Paid SSL, plan renewals at least 30 days in advance and configure email alerts to avoid missing the expiry date.

AsiaGB Hosting customers experiencing SSL renewal issues can contact our Support team 24/7 for assistance with troubleshooting and configuration.

Frequently Asked Questions

How does Let's Encrypt auto-renewal work on DirectAdmin?
DirectAdmin's AutoSSL feature integrates with Let's Encrypt via the ACME protocol. It automatically checks for certificates expiring within 30 days and renews them without any manual intervention required.
Why did my SSL expire even with AutoSSL enabled?
Common causes include incorrect DNS records, firewall blocking port 80, domain not pointing to the server's IP, or hitting Let's Encrypt rate limits (max 5 certificate requests per domain per week).
What is the difference between Let's Encrypt and Paid SSL?
Let's Encrypt is a free DV certificate valid for 90 days that renews automatically. Paid SSL starts from 1,000 THB/year for DV and goes up to OV/EV certificates that display organization names in the browser, suitable for businesses requiring high trust.
What ports are needed for Let's Encrypt AutoSSL?
Let's Encrypt HTTP-01 challenge requires port 80 open from the internet. The domain must have a DNS A record pointing to the server's IP. Alternatively, DNS-01 challenge doesn't need port 80 but requires setting DNS TXT records.
How do I fix an already-expired SSL certificate?
Go to DirectAdmin → SSL Certificates → select Let's Encrypt and click Save to issue a new certificate immediately. If Let's Encrypt fails, contact your hosting provider to check server configuration.
Can I use AutoSSL with a Wildcard SSL on DirectAdmin?
Let's Encrypt supports wildcard certificates via DNS-01 challenge (not HTTP-01). This requires configuring DNS API access. For simpler wildcard SSL, consider purchasing a Wildcard Paid SSL certificate starting from 5,000 THB/year.

Need Hosting with Automatic SSL Support?

AsiaGB Hosting includes Let's Encrypt AutoSSL on all plans, with a Support team ready to help configure SSL. 99% Uptime guarantee. Plans from 500 THB/month.

View Hosting Plans →