Issuing a certificate by hand when AutoSSL cannot cover it

Watch it done · 3 short clips

Screen walkthrough with on-screen captions, no narration. Plays on this page, muted, no sign-in needed. Every name, address and figure on screen is an example.

Most certificates on a normal estate should never need your attention. Automatic issuance covers the ordinary case and renews without being asked. This article is about the remainder, which is small but never reaches zero.

First, work out why automation did not cover it

Doing the manual work before understanding the cause is how people end up doing it again in ninety days. Automatic issuance needs to prove the name belongs to you, so it fails for a small set of reasons:

  • The name does not resolve to this account. The most common cause by far, and no certificate work will fix it.
  • The validation request cannot reach the site. A redirect, a rewrite rule or an access restriction is intercepting it.
  • The name is not the kind that can be validated this way. Wildcards and some internal names fall here.
  • You need a certificate this authority does not issue. Organisation validated, extended validation, or one a client insists on buying elsewhere.

Only the last one genuinely calls for a manual certificate. The first three are configuration problems wearing a certificate costume, and the first two are usually fixed in minutes. Which of the three you are in is answered by the checks in Diagnostics.

The three artefacts, and which one is secret

ArtefactWhat it isWho may see it
Private keyThe half that proves you are youNobody. It stays on the server
Signing requestYour details, wrapped for the authorityThe authority. Public in effect
CertificateThe authority's signed answerEveryone. It is served to visitors

Generate the key and the request on the server that will use them, and let the key stay there. If a supplier offers to generate the key for you and send it over, that is a supplier who has your key.

The order that avoids a bad afternoon

  1. Generate the key and signing request for the exact names the certificate must cover.
  2. Send the request to the authority and complete their validation.
  3. Install the certificate against the right account and the right name.
  4. Include the intermediate chain. This is the step people miss.
  5. Check the result from outside, in a browser and on a phone.

A missing chain is the classic failure here: it works on your desktop, where the chain happens to be cached, and warns on a device that has never seen it. So the check that counts is on a device that has no history with the site.

Keep an inventory, because manual means manual

The whole cost of a hand-issued certificate is not the hour you spend now. It is that it will expire, and nothing will remind you. So the moment it is installed, three things get written down: which names it covers, when it expires, and where the renewal is bought.

The panel's list of secure hosts is the right place to read the current state of the estate, and it is worth a look on the same monthly rhythm as everything else. What it tells you is which names are covered and which are relying on something you have to do yourself. The wider view of what renews on its own is in Control From the Dashboard, and the reviewing habit is in Running Your Estate.

Go back to automatic when you can

Manual certificates are a state to leave, not a state to live in. When the reason for the exception is gone, put the name back under automatic issuance and delete the reminder. One less thing that can expire on a weekend.

Still not sure which way to go?

Tell us what you are building. If it needs less than you think, we will say so.

Talk to us · 24/7/365