Knowledgebase

The AutoSSL certificate renewal may cause a reduction of coverage  Print this Article

The AutoSSL certificate renewal may cause a reduction of coverage

Are you a cPanel user that has received an email with the subject “The AutoSSL certificate renewal may cause a reduction of coverage…”?

If you have then DO NOT WORRY, you’re not alone!

In cPanel version 68 a new feature was added to send email notifications to end users when an AutoSSL certificate renewal processed:

SSL and AutoSSL certificate renewal, expiry, failure, and success notifications

In cPanel version 68, by default, the system automatically sends users notifications about the status of SSL and AutoSSL certificates. These notifications include useful information and URLs users can access to correct a problem. You can enable or disable the following notifications:

In cPanel’s Contact Information  interface (cPanel >> Home >> Preferences >> Contact Information):
  • AutoSSL has renewed a certificate — AutoSSL successfully completed a certificate renewal.
  • AutoSSL certificate expiry — An AutoSSL certificate will expire soon.
  • SSL certificate expiry — A non-AutoSSL certificate will expire soon.

This new feature means that cPanel users are starting to receive emails such as the following:

The system failed to fetch the DCV (Domain Control Validation) file at “http://cpanel.domain.co.uk/.well-known/pki-validation/BC8C01969F8C44363E5026E6A260F53C.txt” because of an error: The system failed to send an HTTP (Hypertext Transfer Protocol) “GET” request to “http://cpanel.domain.com/.well-known/pki-validation/BC8C01969F8C44363E5026E6A260F53C.txt” because of an error: Timed out while waiting for socket to become ready for reading

Other similar errors are also reported in the emails, such as:

The system queried for a temporary file at “http://webdisk.exampledomain.com/.well-known/pki-validation/C14A94680FfdfDF1E93E14EFC.txt”, but the web server responded with the following error: 404 (Not Found). A DNS (Domain Name System) or web server misconfiguration may exist. The domain “webdisk.exampledomain.co.uk” resolved to an IP address “1.2.3.4.5” that does not exist on this server.

Both of these errors are usually due to AutoSSL (the cPanel feature that automatically installs free Comodo or LetsEncrypt SSL certificates on domains) attempting to install certificates on cPanel related sub-domains (webdisk.domain.com or cpanel.domain.com) or on domains that don’t resolve directly to the server. An example of the latter would be when the domain is running via Cloudflare or another CDN.

If your domains resolve directly to the server then there is nothing to worry about, your SSL certificates will be automatically renewed as normal!

For the end user these emails can be both confusing and frustrating and in their infinite wisdom cPanel haven’t added an option to globally disable these emails from being sent, although this feature is planned in an upcoming cPanel v68 release.

Until then, our best advice is simply to disregard the emails.

Was this answer helpful?

Related Articles

How to protect a folder with username and password in cPanel?
You can lock a directory with password by using the cPanel "Password Protected Directories"...
How to protect your website's images from an external website?
External Website can use < img /> tag to display an image from your site somewhere else on...
How to renew a SSL Certificate?
Renewing an SSL Certificate Instructions Renewing SSL certificates is easy; just follow the...
How to restrict directory access by IP address?
In order to secure your admin area from hackers, we recommended you to allow access only from...
All SSL Features.
https://sslfeatures.com/