{"id":154,"date":"2017-11-16T10:36:00","date_gmt":"2017-11-16T10:36:00","guid":{"rendered":"https:\/\/d9.hosting\/blog\/?p=154"},"modified":"2017-11-16T15:38:15","modified_gmt":"2017-11-16T15:38:15","slug":"the-autossl-certificate-renewal-may-cause-a-reduction-of-coverage","status":"publish","type":"post","link":"https:\/\/d9.hosting\/blog\/the-autossl-certificate-renewal-may-cause-a-reduction-of-coverage\/","title":{"rendered":"The AutoSSL certificate renewal may cause a reduction of coverage"},"content":{"rendered":"<p>Are you a cPanel user that has received an email with the subject &#8220;The AutoSSL certificate renewal may cause a reduction of coverage&#8230;&#8221;?<\/p>\n<p>If you have then <strong>DO NOT WORRY<\/strong>, you&#8217;re not alone!<\/p>\n<p>In cPanel version 68 a <a href=\"https:\/\/documentation.cpanel.net\/display\/68Docs\/68+Release+Notes#id-68ReleaseNotes-SSLandAutoSSLcertificaterenewal,expiry,failure,andsuccessnotifications\" target=\"_blank\" rel=\"noopener\">new feature was added<\/a> to send email notifications to end users when an AutoSSL certificate renewal processed:<\/p>\n<blockquote>\n<h4 id=\"id-68ReleaseNotes-SSLandAutoSSLcertificaterenewal,expiry,failure,andsuccessnotifications\">SSL and AutoSSL certificate renewal, expiry, failure, and success notifications<\/h4>\n<p>In cPanel &amp; WHM version 68, by default, the system automatically sends users notifications about the status of SSL and AutoSSL certificates. These notifications include useful information and URLs users can access to correct a problem. You can enable or disable the following notifications:<\/p>\n<p>In WHM&#8217;s<em>\u00a0<a href=\"https:\/\/documentation.cpanel.net\/display\/68Docs\/Contact+Manager\">Contact Manager<\/a>\u00a0<\/em>\u00a0interface (<em>WHM &gt;&gt; Home &gt;&gt; Server Contacts &gt;&gt; Contact Manager<\/em>):<\/p>\n<ul>\n<li><em>AutoSSL certificates expiring<\/em>\u00a0\u2014 An account&#8217;s AutoSSL certificate expires soon.<\/li>\n<li><em>Installation of AutoSSL certificates<\/em>\u00a0\u2014 AutoSSL installed an SSL certificate.<\/li>\n<li><em>Installation of purchased SSL certificates<\/em>\u00a0\u2014 The system installed SSL certificates that a user purchased through the cPanel Market.<\/li>\n<li><em>SSL Certificate Expiration<\/em>\u00a0\u2014 A service-level SSL certificate has expired.<\/li>\n<li><em>SSL Certificate Expires Soon<\/em>\u00a0\u2014 An account&#8217;s SSL certificate expires soon.<\/li>\n<li><em>SSL certificates expiring<\/em>\u00a0\u2014 An account&#8217;s SSL certificate expires soon.<\/li>\n<\/ul>\n<p>In cPanel&#8217;s<em>\u00a0<a href=\"https:\/\/documentation.cpanel.net\/display\/68Docs\/Contact+Information\">Contact Information<\/a>\u00a0<\/em>\u00a0interface (<em>cPanel &gt;&gt; Home &gt;&gt; Preferences &gt;&gt; Contact Information<\/em>):<\/p>\n<ul>\n<li><em>AutoSSL has renewed a certificate<\/em>\u00a0\u2014 AutoSSL successfully completed a certificate renewal.<\/li>\n<li><em>AutoSSL certificate expiry<\/em>\u00a0\u2014 An AutoSSL certificate will expire soon.<\/li>\n<li><em>SSL certificate expiry<\/em>\u00a0\u2014 A non-AutoSSL certificate will expire soon.<\/li>\n<\/ul>\n<\/blockquote>\n<p>This new feature means that cPanel users are starting to receive emails such as the following:<\/p>\n<blockquote><p>The system failed to fetch the DCV (Domain Control Validation) file at \u201chttp:\/\/cpanel.domain.co.uk\/.well-known\/pki-validation\/BC8C01969F8C44363E5026E6A260F53C.txt\u201d because of an error: The system failed to send an HTTP (Hypertext Transfer Protocol) \u201cGET\u201d request to \u201chttp:\/\/cpanel.domain.co.uk\/.well-known\/pki-validation\/BC8C01969F8C44363E5026E6A260F53C.txt\u201d because of an error: Timed out while waiting for socket to become ready for reading<\/p><\/blockquote>\n<p>Other similar errors are also reported in the emails, such as:<\/p>\n<blockquote><p>The system queried for a temporary file at \u201chttp:\/\/webdisk.exampledomain.co.uk\/.well-known\/pki-validation\/C14A94680FfdfDF1E93E14EFC.txt\u201d, but the web server responded with the following error: 404 (Not Found). A DNS (Domain Name System) or web server misconfiguration may exist. The domain \u201cwebdisk.exampledomain.co.uk\u201d resolved to an IP address \u201c1.2.3.4.5\u201d that does not exist on this server.<\/p><\/blockquote>\n<p>Both of these errors are usually due to AutoSSL (the cPanel feature that automatically installs <a href=\"https:\/\/d9.hosting\/free-comodo-ssl-certificates.php\" target=\"_blank\" rel=\"noopener\">free Comodo or LetsEncrypt SSL certificates<\/a> on domains) attempting to install certificates on cPanel related sub-domains (webdisk.domain.com or cpanel.domain.com) or on domains that don&#8217;t resolve directly to the server. An example of the latter would be when the domain is running via Cloudflare or <a href=\"https:\/\/d9.hosting\/website-firewall.php\" target=\"_blank\" rel=\"noopener\">another CDN<\/a>.<\/p>\n<p>If your domains resolve directly to the server then there is nothing to worry about, your SSL certificates will be automatically renewed as normal!<\/p>\n<p>For the end user these emails can be both confusing and frustrating and in their infinite wisdom cPanel haven&#8217;t added an option to globally disable these emails from being sent, although this feature is planned in an <a href=\"https:\/\/forums.cpanel.net\/threads\/ssl-notifications-in-cpanel-68.614395\/page-3#post-2498103\" target=\"_blank\" rel=\"noopener\">upcoming cPanel v68 release<\/a>.<\/p>\n<p>Until then, our best advice is simply to disregard the emails.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Are you a cPanel user that has received an email with the subject &#8220;The AutoSSL certificate renewal may cause a reduction of coverage&#8230;&#8221;? If you have then DO NOT WORRY, you&#8217;re not alone! In cPanel version 68 a new feature was added to send email notifications to end users when an AutoSSL certificate renewal processed: SSL and AutoSSL certificate renewal, expiry, failure, and success notifications In cPanel &amp; WHM version 68, by default, the system automatically sends users notifications about&#8230;<\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"https:\/\/d9.hosting\/blog\/the-autossl-certificate-renewal-may-cause-a-reduction-of-coverage\/\"> Read More<span class=\"screen-reader-text\">  Read More<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":160,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"_links":{"self":[{"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/posts\/154"}],"collection":[{"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/comments?post=154"}],"version-history":[{"count":7,"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/posts\/154\/revisions"}],"predecessor-version":[{"id":162,"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/posts\/154\/revisions\/162"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/media\/160"}],"wp:attachment":[{"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/media?parent=154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/categories?post=154"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/d9.hosting\/blog\/wp-json\/wp\/v2\/tags?post=154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}