An SSL/TLS certificate encrypts the traffic between your website and your visitors and provides the padlock and HTTPS in the address bar. Without a valid certificate, browsers display warnings and visitors leave. Fortunately, managing this is easy with the right tools: you install a certificate, ensure automatic renewal, and occasionally check that everything is correct. This article explains what you need to know and which steps you can take yourself.
What is an SSL/TLS certificate and why do you need it
SSL and TLS are protocols that encrypt data between a website and a visitor. Without a certificate, data such as passwords, contact forms, and payment information can in principle be intercepted. With a valid certificate, the visitor sees a padlock in the browser and all communication is sent encrypted.
For entrepreneurs and website administrators, this is important for several reasons:
- Trust: visitors expect a secure connection, especially with forms or a webshop.
- Search engines: HTTPS is part of how search engines evaluate a website.
- Compliance: when processing personal data, an encrypted connection is part of careful data handling.
- Preventing error messages: an expired certificate immediately causes warnings in the browser, which scares off visitors.
Installing a certificate in Plesk
If your hosting runs on Plesk, installing a certificate is a matter of a few clicks. Most providers, including Tandata, offer free Let’s Encrypt certificates that can be activated directly through the control panel.
Log in to Plesk
Open your Plesk control panel and select the domain for which you want to set up a certificate.
Go to Security
Look in the menu for the option for SSL/TLS certificates or Let’s Encrypt.
Choose Let’s Encrypt
Select the free certificate, optionally enter an email address, and start the request.
Domain validation
Plesk automatically checks whether you own the domain, usually via DNS or HTTP validation.
Certificate active
After validation, the certificate is immediately active and your website shows HTTPS.
Do you have multiple subdomains, for example for a webshop or customer portal? Then a wildcard certificate can be useful, so you don’t have to arrange something separately for each subdomain. Also keep a close eye on your domain names and associated DNS settings, as these are needed for validation.
Automatic renewal and checking
Let’s Encrypt certificates are valid for a limited period. If a certificate is not renewed in time, a warning appears in the browser and visitors may leave. Automatic renewal is therefore not an extra option, but a basic requirement for a reliable website.
In Plesk, you enable this in the certificate settings, usually with a checkbox for ‘automatically renew’. Once set up, you don’t need to look at this again.
You can always check the status of a certificate yourself by clicking the padlock in your browser’s address bar. For a more thorough analysis, for example of the complete configuration, free online testing tools are available.
Solving common problems
Most certificate issues have one of the following causes:
- Expired certificate: this usually happens because automatic renewal is not set up correctly. In that case, install a new certificate and check the renewal setting.
- Incorrect domain validation: if DNS settings have recently been changed, validation may fail. Check whether your domain correctly points to the right server.
- Mixed content: a page loads via HTTPS, but still contains references to images or scripts via HTTP. This causes an insecure warning despite a valid certificate.
- Email and certificates: a correct secure connection is also important for business email. See our page about business email for more explanation about this.
Can’t figure it out yourself, or unsure about the correct settings after a migration? Check the knowledge base or contact us via support. Considering switching to another hosting provider and want to know how certificates are handled in that process? Check out switching to Tandata.
Frequently Asked Questions
Can I use a wildcard certificate for subdomains?
Yes, a wildcard certificate covers all subdomains of a domain with a single certificate, making management easier when you have many subdomains.
My certificate has expired, what now?
Remove the old certificate in Plesk and install a new free certificate. Then immediately enable automatic renewal to prevent this from happening again.
Does a Let’s Encrypt certificate cost anything?
No, Let’s Encrypt is free. The only responsibility that lies with you is making sure the certificate is automatically renewed.
How do I know if my certificate is still valid?
Click the padlock in your browser’s address bar for certificate details, or use an online SSL testing tool for a more extensive check.
Does a renewed certificate work immediately without a restart?
With good interaction between the web server and control panel, a renewed certificate is applied automatically, without you having to manually restart anything.
Conclusion
An SSL/TLS certificate is essential for a secure and reliable website. With Plesk, you easily install a free certificate, and by enabling automatic renewal you prevent expired certificates and annoying browser warnings. Check occasionally that everything still works correctly, and your website remains secure without any worries.