On this page
A wildcard certificate on cPanel covers hostnames like *.example.com under one name. It does not cover the apex domain example.com itself, and it only matches one label, so a.b.example.com is out of scope. AutoSSL with HTTP-01 cannot prove a wildcard, so you install a paid or DNS-01 wildcard yourself in SSL/TLS when you truly need one. For a small set of fixed names, separate DV certificates from AutoSSL are usually simpler.
When two certificates beat a wildcard
If you only need the apex and www, let AutoSSL issue two ordinary DV certificates. The same approach works for a shop site plus something like mail.example.com. A wildcard starts to make sense when you create many subdomains on a steady schedule and you can complete DNS-01 validation or work with a vendor that issues through your DNS API. cPanel will install a wildcard certificate you paste into SSL/TLS. It will not obtain one through HTTP-01 on its own.
Treat the private key with care. That key unlocks every matching subdomain, including names you have not created yet. Avoid placing a shared wildcard on a server that also hosts customer subdomains you do not control. The blast radius is larger than the convenience.
How renewal works when AutoSSL is not in charge
AutoSSL will not manage a wildcard it could not issue. A paid wildcard you forget to renew can take down every name it covers at once. Put the expiry on your calendar and set a reminder ahead of the vendor notice. When the new certificate arrives, install the leaf and chain in SSL/TLS, then confirm the apex and at least one subdomain show the new dates.
By default, rely on AutoSSL DV certificates per hostname. Reach for a wildcard only when you truly generate many names and you have a renewal process you will follow. SSL Labs grades care about the chain and protocols, not whether the certificate was a wildcard.
What you see in SSL/TLS Status
cPanel lists a wildcard you installed as a certificate you manage, not one AutoSSL owns. If both a wildcard and a DV certificate for www are present, the vhost uses one of them, so check which name is active. After a paid wildcard expires, AutoSSL may issue DV certificates for names it can prove and leave others stuck on the dead wildcard. Remove the expired certificate so AutoSSL can cover the hostnames it is allowed to validate.
Tagged
Was this article helpful?
Be the first to rate this article.



