Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

AutoSSL: exclude parent domain - will renewal work?

Discussion in 'Security' started by chuckcintron, Jul 9, 2018.

  1. chuckcintron

    chuckcintron Member

    Joined:
    May 17, 2012
    Messages:
    18
    Likes Received:
    0
    Trophy Points:
    51
    cPanel Access Level:
    Root Administrator
    All I need is for the www subdomain to be AutoSSL/validated. So, I am manually setting all domains to be excluded from AutoSSL, with the exception of www.

    This means I am excluding the parent domain.

    My testing indicates that AutoSSL will still get a certificate for the domain, and www ends up being validated. It does give the 'canned' message however:

    Expires on October 8, 2018. The certificate will renew via AutoSSL when the parent domain “example.com” renews.

    My question: Will the www subdomain renew automatically (and successfully), even if I have marked the parent domain to be excluded from AutoSSL?
     
  2. cPanelLauren

    cPanelLauren Forums Analyst
    Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    2,748
    Likes Received:
    187
    Trophy Points:
    143
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    Hi @chuckcintron

    The process assumes you'll be renewing the certificate with the parent domain but as long as the DCV process is able to complete the certificate should be renewed.

    Thanks!
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. chuckcintron

    chuckcintron Member

    Joined:
    May 17, 2012
    Messages:
    18
    Likes Received:
    0
    Trophy Points:
    51
    cPanel Access Level:
    Root Administrator
    thank you @cPanelLauren

    But I really want to be sure about this. Is there any way (other than waiting 90 days to see if my many domains renew) to get a level of confidence that AutoSSL will try to DCV and renew the www domain, since it is marked "enabled" -- even if the parent domain is marked "disabled"?

    It's either this answer or my other thread that is still 'in progress' In Progress - [CPANEL-21489] autoSSL DCV to www instead of base domain?

    ...I have to get to the point where I am confident this entire long-pole part of the process will actually work when the time comes.
     
  4. cPanelLauren

    cPanelLauren Forums Analyst
    Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    2,748
    Likes Received:
    187
    Trophy Points:
    143
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    Hi @chuckcintron

    The other thread is still in progress - I did check up on it and they have not answered the inquiry as of yet though it is in on their radar.

    For this, if the initial request goes through automatically (which it did on my test server) you can be confident subsequent checks including renewals will. I don't, unfortunately, have a way to prove this further.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice