Start paid-certificate renewal before expiry and keep automated validation working for Let’s Encrypt.
An SSL certificate confirms control of a domain and encrypts traffic to the service named in the certificate. It does not make vulnerable application code safe, and it only covers the hostnames included in the certificate.
Before you start
- Confirm the active product or addon and the domain or user it protects.
- Record the current settings before changing them.
- Allow for DNS caching and avoid making unrelated DNS changes during the same maintenance window.
Step-by-step
- Check the expiry and renewal status.
- Complete any new validation.
- Install the renewed certificate if it is not automated.
- Test every hostname.
- Remove obsolete certificates only after successful cutover. Read the confirmation text because the action may remove data or interrupt service.
Confirm the result
- The Customer Portal shows the intended invoice, transaction or service status and the effective date is clear.
- No duplicate payment, renewal or cancellation request has been created while waiting for processing.
Common problems
| Symptom | Likely cause | What to do |
|---|---|---|
| Certificate issuance fails. | The domain does not resolve to the hosting server, an incorrect AAAA record exists, or validation requests are redirected or blocked. | Confirm public A and AAAA answers, allow HTTP validation to reach the account and retry only after DNS is correct to avoid rate limits. |
| The browser still shows an old or invalid certificate. | A proxy, CDN, alternate hostname or cached connection is presenting a different certificate. | Check the certificate actually served for each hostname and test both IPv4 and IPv6 paths before reinstalling anything. |
Important notes
- Make production changes in a planned window, keep the old configuration recorded and avoid changing several dependent services at the same time.
When to contact Tudor Internet
Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:
- The addon service and protected domain or user
- The plan or licence level
- The time the issue started and exact message
- Screenshots with credentials, tokens and personal data removed
Related articles
- Generate a certificate signing request
- Install a paid SSL certificate
- Choose between Let’s Encrypt and a paid SSL certificate
- Fix mixed-content warnings
- Choose an SSL certificate
Last reviewed: 2026-07-18.