📋 Table of Contents
- Why SSL Certificates Expire Unexpectedly
- How AutoSSL Works on DirectAdmin
- Enabling AutoSSL on DirectAdmin
- First-Time Let's Encrypt Setup
- Checking Renewal Status
- Common Problems and Solutions
- Renewing Paid SSL Certificates
- Let's Encrypt vs Paid SSL Comparison
- SSL Management Best Practices
- Frequently Asked Questions
An expired SSL certificate is one of the most common problems website owners face. When an SSL certificate expires, browsers display "Your connection is not private," immediately driving visitors away. This guide covers how to set up automatic SSL renewal on DirectAdmin for both Let's Encrypt and Paid SSL, so you never have to worry about certificate expiry again.
1. Why SSL Certificates Expire Unexpectedly
SSL certificates have a limited lifespan — Let's Encrypt certificates last only 90 days, while Paid SSL certificates last 1 year or more. Without an automatic renewal system, website owners must remember expiry dates and renew manually, which is easy to forget.
- Let's Encrypt: 90-day validity; renew at least 30 days before expiry
- Paid SSL (DV/OV/EV): 1-year validity; must purchase renewal before expiry
- Wildcard SSL: Covers all subdomains; 1-year validity
2. How AutoSSL Works on DirectAdmin
DirectAdmin includes an AutoSSL feature that integrates with Let's Encrypt via the ACME protocol. The process works as follows:
1 Certificate scan every 12 hours to find certificates expiring within 30 days
2 Renewal request sent to Let's Encrypt CA via HTTP-01 or DNS-01 challenge
3 Domain ownership verification by Let's Encrypt accessing a file in /.well-known/acme-challenge/
4 New certificate saved to DirectAdmin and Apache/Nginx automatically reloaded
3. Enabling AutoSSL on DirectAdmin
Enabling AutoSSL on DirectAdmin Hosting can be done through the DirectAdmin User Panel:
1 Log in to DirectAdmin User Panel (usually port 2222)
2 Click SSL Certificates under "Your Account"
3 Select "Let's Encrypt" option at the bottom
4 Check the "AutoSSL" or "Auto-renew" checkbox
5 Click Save — the system will issue a new certificate and configure auto-renewal
domain.com and www.domain.com in the domain field.
4. First-Time Let's Encrypt Setup
If you haven't installed SSL on DirectAdmin before, follow these steps first:
- Log in to DirectAdmin → SSL Certificates
- Select Let's Encrypt (not "Paste a pre-generated certificate")
- Verify the domain has a correct DNS A record pointing to the server's IP
- Choose the domains and subdomains to cover
- Click Save — wait 1-2 minutes for the certificate to be issued
- Enable Force HTTPS Redirect via DirectAdmin → htaccess Manager
5. Checking Renewal Status
How to verify your SSL will renew successfully:
Via DirectAdmin
- Go to SSL Certificates → check the Expiry Date
- If expiry is within 30 days, the system will show "Renewing soon"
Via Browser
- Click the 🔒 in the address bar → Certificate → check expiry date
- Or use AsiaGB's free SSL Checker
Via Command Line (for VPS)
openssl s_client -connect domain.com:443 -servername domain.com 2>/dev/null \
| openssl x509 -noout -dates
6. Common Problems and Solutions
| Problem | Cause | Solution |
|---|---|---|
| SSL expires despite AutoSSL enabled | Port 80 blocked or DNS incorrect | Check firewall rules and DNS records |
| "Too Many Requests" from Let's Encrypt | More than 5 certificate requests per domain per week | Wait 1 week then retry |
| Certificate issued but browser still shows "not secure" | Mixed content (images/scripts using HTTP) | Update all URLs to HTTPS |
| Wildcard domain not covered | Certificate issued without wildcard | Re-issue certificate with *.domain.com |
| AutoSSL not running automatically | DirectAdmin cron job not working | Contact hosting provider to check |
7. Renewing Paid SSL Certificates
For Paid SSL certificates (RapidSSL, GeoTrust, Symantec), renewal must be done through the SSL provider:
1 Purchase a new certificate at least 30 days before expiry at billing.in.th
2 Generate a CSR via DirectAdmin → SSL Certificates → "Paste a pre-generated certificate" → Generate CSR
3 Submit CSR to CA for domain validation
4 Receive certificate files via email and upload to DirectAdmin
5 Verify that the browser shows 🔒 correctly
8. Let's Encrypt vs Paid SSL Comparison
| Feature | Let's Encrypt | Paid SSL (DV) | Paid SSL (OV/EV) |
|---|---|---|---|
| Price | Free | From 1,000 THB/year | From 4,000 THB/year |
| Validity | 90 days | 1 year | 1 year |
| Renewal | Automatic (AutoSSL) | Manual purchase required | Manual purchase required |
| Shows organization name | No | No | Yes (OV/EV) |
| Warranty | None | Up to $10,000+ | Up to $1.5M |
| Best for | Blogs, personal sites | Small businesses | E-commerce, finance |
9. SSL Management Best Practices
- Always enable AutoSSL on DirectAdmin for automatic Let's Encrypt renewal
- Force HTTPS Redirect via .htaccess or DirectAdmin to prevent mixed content
- Set email alerts for SSL expiry 30 days in advance (configurable in DirectAdmin)
- Check HSTS (HTTP Strict Transport Security) configuration to enhance security
- Test SSL with SSL Labs or AsiaGB's SSL Checker at least every 3 months
- Back up private keys securely in case you need to re-issue certificates
- Ensure complete certificate chain to avoid "incomplete chain" browser errors
10. Summary
Setting up automatic SSL renewal on DirectAdmin is straightforward. Simply enable AutoSSL with Let's Encrypt through the SSL Certificates section in DirectAdmin Panel, and the system will handle everything automatically. For websites requiring Paid SSL, plan renewals at least 30 days in advance and configure email alerts to avoid missing the expiry date.
AsiaGB Hosting customers experiencing SSL renewal issues can contact our Support team 24/7 for assistance with troubleshooting and configuration.