Transport layer · Beginner · 0–20 minutes
AutoSSL, Domain Validation and the Names on the Cert
The padlock is fine on the bare domain and broken on www, and the certificate page shows a warning you cannot decode.
The short answer
On this platform a free certificate issues and installs itself as soon as the hostname resolves to the server — so for most sites the correct action is to point DNS and check, not to install anything. Validation is automatic: the authority asks for a token at that hostname, the server serves it, the certificate is issued.
What goes wrong is coverage rather than encryption. A certificate names specific hostnames, and a visitor arriving at a name that is not on the list gets a mismatch warning that looks like a catastrophe and is a list problem. Read SSL/TLS Status and it will tell you which name is missing.
By the HostingFast team · Reviewed 12 August 2026
Beginner
Difficulty grade
5
Stages
Free
Support cost
Proven
Verified on
Assumed knowledge: you can point a DNS record and open a panel page. Most of this guide is about reading the status page correctly rather than about installing anything.
The manual path for a purchased certificate is here too, along with an honest note on what a paid certificate buys — which is validation scope, not stronger encryption.
How the certificate gets there without you
AutoSSL asks a certificate authority for a certificate covering the hostnames on the account. The authority requires proof of control, and the standard proof is serving a token at a well-known path over HTTP on that hostname — which the server does automatically, then discards.
Renewal follows the same route well before expiry, unattended. The consequence worth remembering is that the whole mechanism depends on the hostname resolving here: certificates chase DNS, and nothing about the process works from the panel alone.
Reading SSL/TLS Status for coverage
The panel page lists every domain and subdomain on the account with its certificate state. A certificate carries a list of subject alternative names, and a hostname absent from that list is not covered, however healthy the certificate looks.
That is the mechanism behind the commonest complaint on this topic: the bare domain is green and www is not, or a new subdomain shows a warning. The page names the specific hostname, which turns a vague browser error into a one-line fix.
Why issuance stalls
Three causes cover nearly all of it. The hostname does not resolve to this server yet, so validation cannot succeed. A CAA record in the zone names a different certificate authority, which forbids ours from issuing — and produces no visible error at all. Or a redirect or firewall rule blocks the validation path before the token can be served.
Check them in that order: resolution first with a lookup, then the CAA record, then whether the well-known path is reachable over plain HTTP. A stalled issuance is always one of those three rather than a mystery.
Paid certificates, and what TLS actually costs a page
For organisation validation, extended validation or a wildcard, generate the CSR in the panel, submit it to the authority, and paste the signed certificate back under Install. Five fields and five minutes, and the only part that differs is who verified you.
On performance: a TLS handshake adds a round trip on a cold connection, then session resumption and HTTP/2 multiplexing recover it — and HTTP/2 requires TLS in every browser that implements it, so https is faster than plain HTTP for anything beyond a single request. Free DV encrypts identically to the paid tiers; what you buy is validation scope.

The platform this issuance was observed on
Every screen and behaviour here was observed on the stack we operate: the same AutoSSL implementation, the same status page, the same defaults. Nothing is generalised from another host.
NVMe storage and LiteSpeed caching are on every tier, from the smallest plan upwards — speed is the baseline rather than an upsell.
- Validation explained, not skipped
- Coverage read off the SAN list
- Stalls narrowed to three causes
- Engineers on shift at any hour
Why HostingFast
Standard on every plan
Validation explained
How domain control is proved, so a stalled issuance points at something specific rather than nowhere.
SAN coverage checked
Every hostname on the certificate listed, with the one that is missing named for you.
CAA considered
A record naming a different authority blocks issuance and produces no visible error whatsoever.
Free and paid compared honestly
Identical encryption; paid tiers buy validation scope and wildcard coverage, never stronger crypto.
The handshake cost, in context
One extra round trip on a cold connection, recovered by resumption and by HTTP/2 needing TLS anyway.
Issued and renewed unattended
Free SSL on every plan, renewed automatically well before it can expire.
Quick Start
From order to online
- 1
Point DNS at the server first
Validation requires the hostname to resolve here. Everything else in this guide waits on that, and nothing in the panel can substitute for it.
- 2
Let AutoSSL run, then read SSL/TLS Status
For most sites the certificate is already installed by the time you look. The status page lists every hostname and its state.
- 3
Chase a missing hostname through three checks
Does it resolve here? Is there a CAA record naming another authority? Can the validation path be reached over plain HTTP? One of those three is the answer.
- 4
Add a CSR-based certificate only if you need OV, EV or a wildcard
Generate the CSR in the panel, submit it, paste the result under Install SSL. Free DV already gives you the same encryption.
- 5
Force https and verify the chain externally
Enable the redirect, then check with an external SSL tester: chain complete, no mismatch, no expired intermediate. That is the finished state.
Built In
Loaded onto every plan
- Free SSL on every plan, renewed automatically before it can expire
- LiteSpeed caching in the server itself, not bolted on by plugin
- NVMe SSD storage on every tier, not just the expensive ones
- cPanel — the panel most of the industry already automates against
- Migration handled by our engineers at no charge
- First year of the domain included when you order annually
- Daily backups with restores you trigger yourself from the panel
- Engineers on shift every hour of every day, not a queue that opens at nine
- Money-back window: 30 days on hosting plans, 7 on reseller
- No setup fee on any plan, ever
Frequently Asked
What people ask us most often
Why did AutoSSL skip one subdomain?
Because one of three things is true for that specific hostname: it does not resolve to this server, a CAA record in the zone permits only a different authority, or the validation request could not reach the well-known path — often because a redirect or a firewall rule intercepted it. Check in that order and the answer appears quickly.
Does a paid certificate make the connection more secure or faster?
Neither. The encryption is identical — the same cipher suites and the same key exchange. What the paid tiers add is who the authority verified and how many names the certificate covers: organisation or extended validation, or a wildcard for every subdomain at once. Speed does not enter into it.
Do you handle the migration, and what does it cost?
Yes. Open a ticket with your current host's login details and we bring everything across — files, databases, mailboxes, configuration. You review the copy before DNS moves, and your old site keeps taking traffic right up until the new one is serving it, so visitors never hit a gap.
Are backups self-service, or do restores go through a ticket?
Yes — every plan gets a daily backup, and the restore runs from your panel in minutes: files, databases or both, at three in the morning with no ticket queue in the way. Keeping an extra copy offsite is still a smart habit, and nothing here prevents it.
Keep reading
How to Add SSL to WordPress
Every page over https, with the mixed-content references swept out of the database.
How to Set Up Browser Caching
Cache-Control and ETag headers set so a repeat visit costs almost no bytes.
SSL Certificate (Glossary)
What the certificate actually asserts, and what it does not, in one screen.
AI Website Builder
Describe the site and the AI drafts it, on real hosting rather than a preview.
WordPress Hosting
WordPress on LiteSpeed with staging and daily backups already wired in.
Changing hosts? Run through our checklist first.
A straightforward sequence for a switch your visitors never feel: which files move first, how to shift email across without losing a single message, the right moment to repoint DNS, and the two mistakes behind almost all the downtime we get asked to rescue.
Encrypt it and forget it.
Free SSL renewed automatically, free migration, NVMe on every tier, and engineers on shift around the clock.
View AI Website Builder plans