HTTPS encrypts the connection between a visitor's browser and your website. Logins, forms, and payment details stay private in transit. A certificate is the digital ID that proves the name in the address bar matches this site and turns that encryption on.
On Beginner and Standard shared hosting (cPanel) in Australia, AutoSSL issues a Let's Encrypt certificate once the name points at this account. Open cPanel from the portal. Do not guess a hostname.
On a VPS, install TLS yourself with Certbot. Credentials and the console are on that server in the portal.
On a dedicated server, open a support ticket and we will walk you through a certificate.
A step is unclear, or AutoSSL still has no certificate after DNS has updated? Open a support ticket and we will help.
What SSL/TLS does
SSL (Secure Sockets Layer) and TLS (Transport Layer Security) are the protocols behind HTTPS. TLS is the current version. People still say SSL.
They do three jobs:
- Encrypt. Data between the browser and the site is unreadable on the network.
- Authenticate. The certificate shows the name the visitor typed belongs to this server, not an imposter.
- Integrity. An attacker on the path cannot silently change the page in transit.
The padlock and https:// mean the browser accepted that certificate for this name.
HTTP vs HTTPS
| Feature | HTTP | HTTPS |
|---|---|---|
| Encryption | None. The page and forms travel in plain text. | The whole request and response are encrypted. |
| Address bar | Domain only, often labelled Not secure. | Padlock and https://. |
| Use | Almost never for a public site. | Every site we host. Especially anything with a login or a form. |
| Search | Search engines treat this as a weaker signal. | HTTPS is the expected default. |
Anyone on the same Wi-Fi or network path can read an HTTP login. HTTPS stops that.
How a certificate works
- The browser connects to the site on 443.
- The server sends its certificate (public key plus the names it covers).
- The browser checks that a trusted Certificate Authority (CA) issued it, that it has not expired, and that the name matches.
- Browser and server agree session keys using that public key.
- Everything after that is encrypted both ways.
- The padlock appears.
Let's Encrypt is the CA AutoSSL uses on this hosting. Browsers already trust it.
Types of certificates
Domain Validation (DV) is what AutoSSL issues. It proves you control the domain. It does not verify a company name. That is enough for blogs, apps, shops, and almost every site on our shared hosting.
Organisation Validation (OV) and Extended Validation (EV) add a business check. Today's browsers still show the padlock and the domain. They no longer put an organisation name or a green bar in the address bar. You do not need OV or EV for HTTPS to work here.
Wildcard certificates cover a name and every direct subdomain (*.yourdomain.com). AutoSSL does not issue a * wildcard. It issues DV certificates for the specific names on this account that already resolve here (the apex, www, addons, aliases, subdomains).
Multi-domain (SAN) certificates list several hostnames on one cert. AutoSSL does this for you as those names appear and resolve.
For a site on our hosting, stay on AutoSSL. Do not buy a certificate from another CA as the first step. If you already have a certificate and key file we need to install, open a support ticket.
Shared hosting: turn on HTTPS
The name must already resolve to this account. AutoSSL proves control over HTTP. If DNS still points elsewhere, no certificate is issued.
If the domain is registered with us, it is already on AtlasDNS. Open Domains → the domain → DNS in the portal and keep the A records for @ and www on this account's shared IP (cPanel General Information → Shared IP Address).
If the domain is registered elsewhere, set its nameservers to ours, then manage records in the portal:
ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
AtlasDNS is the default. Do not send the domain to a third-party DNS host. Full steps: Point your domain at your hosting. Changes are often quick, but they can take a while to show everywhere. See DNS propagation explained.
Then:
- Sign in at the portal, open the hosting service, and click Log in to cPanel.
- Open SSL/TLS Status.
- Find the domain and
www(and any addon, alias, or subdomain you need). - Run AutoSSL if a certificate is not there yet, then wait for a valid cert on that row.
- In cPanel Domains, turn Force HTTPS Redirect on for that name.
- Visit
https://yourdomain.comandhttps://www.yourdomain.comin a private window.
You do not need a 301 in Redirects for same-host HTTP to HTTPS. See Set Up a Domain Redirect. Do not paste a RewriteRule into .htaccess as the first HTTPS step. Force HTTPS Redirect is the control on this hosting.
Skip CAA records unless you have a reason. A CAA that names the wrong issuer stops AutoSSL. If you want one set, open a support ticket. See DNS record types explained.
After the padlock is there
- Bookmarks and old
http://links follow Force HTTPS Redirect. - Search engines pick the HTTPS URL up over time.
- WordPress: in Settings → General, set WordPress Address and Site Address to the
https://URLs, then save. Prefer WordPress Toolkit or Installatron for a new site. See Secure Your WordPress Site. - A lock with mixed-content warnings (images, scripts, or CSS still loaded over
http://) is a different job: Fix "Not secure" and mixed-content warnings.
Website HTTPS is not mailbox TLS. Shared-hosting mail uses IMAP 993, POP 995, and SMTP 587 or 465. See General IMAP/POP/SMTP Mail Settings Explained.
VPS
There is no AutoSSL on a stock VPS. Install a certificate on the server. Certbot (Let's Encrypt) is the usual path: Get a Free SSL Certificate with Certbot.
Point the name at the VPS IPv4 shown on that service in the portal first. Open 80 and 443 on the host firewall. See Set up a UFW firewall on Ubuntu and First steps on a new VPS.
Certificate maintenance
- AutoSSL renews Let's Encrypt certificates on its own. You do not upload a file or mark a calendar date.
- Certbot on a VPS renews with its timer. Keep that timer enabled.
- A certificate we installed from a file you supplied does not renew itself. Open a support ticket before it expires if you need a replacement installed.
- An expired or mismatched certificate makes browsers show a warning and block the page. Fix it before visitors hit that screen.
If SSL/TLS Status still shows no certificate after the name has resolved here, open a support ticket. Tell us the domain.
Why HTTPS matters
- Visitors see a padlock instead of Not secure.
- Search engines expect HTTPS.
- Login forms and anything that collects an email, a password, or a card number must use it.
- Payment processors will not accept a checkout on plain HTTP.
If the site collects any of that, leave Force HTTPS Redirect on. Most sites on this hosting are HTTPS the same day DNS points here.
Need hosting first? Browse shared hosting, VPS, or dedicated. After the account is ready: Getting started after you order hosting.
Do not wait on an email thread. Open a support ticket and we will help.
Related
- Keep your website secure
- Fix "Not secure" and mixed-content warnings
- Set Up a Domain Redirect
- Point your domain at your hosting
- DNS propagation explained
- DNS record types explained
- Get a Free SSL Certificate with Certbot
- Set up a UFW firewall on Ubuntu
- First steps on a new VPS
- Install WordPress
- Secure Your WordPress Site
- Getting started after you order hosting
- General IMAP/POP/SMTP Mail Settings Explained