How-toSSL & security
How to install a free SSL certificate
- Reading time
- 5 min
- Last updated
- 22 Sep 2026
Paid SSL made sense when certificates were hard to get. They are not any more: Let's Encrypt issues free, browser-trusted certificates, cPanel renews them automatically, and the padlock is identical to a ₹5,000 one. Here is how to turn it on and, more importantly, how to make the whole site actually use it.
-
01
Check whether you already have one
Go to Security → SSL/TLS Status. Every domain and subdomain on the account is listed with its certificate state. A green lock means it is already covered — on FasterHost, AutoSSL runs on every new domain, so usually it is.
-
02
Run AutoSSL
Tick any domain showing as unsecured and click Run AutoSSL. It takes a few minutes.
AutoSSL proves you control the domain by fetching a file over HTTP, so it can only succeed if the domain already resolves to this server. A domain still pointing at your old host will fail here — point the domain first.
-
03
Force HTTPS for every visitor
A certificate does nothing on its own; the site has to redirect. In cPanel go to Domains and switch on Force HTTPS Redirect for each domain.
If you would rather do it in
.htaccess, put this above any other rewrite rules:RewriteEngine On RewriteCond %{HTTPS} !=on RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]Use a 301, not a 302. A temporary redirect tells Google the HTTP version is still the real one.
-
04
Fix mixed content
If the padlock shows a warning, something on the page is still loading over
http://— usually an image, font or script hard-coded in an old theme.On WordPress, update the site address first under Settings → General, then run a search-and-replace across the database for
http://yourdomain→https://yourdomain. WP-CLI does it safely, serialised data included:wp search-replace 'http://example.in' 'https://example.in' --all-tables --preciseTake a backup before any search-and-replace.
Is a free certificate as good as a paid one?
For encryption, yes — identical. Let's Encrypt uses the same algorithms and the same browser trust stores. The differences are commercial rather than technical:
- Validation level. Free certificates are domain-validated. Organisation and Extended Validation certificates verify the company behind the domain, which a bank might want and a blog does not.
- Warranty. Paid certificates carry a financial warranty. It almost never pays out.
- Lifetime. Let's Encrypt certificates last 90 days and renew automatically. Paid ones last a year and you remember to renew them once, then forget.
For the overwhelming majority of Indian sites — business sites, blogs, stores taking UPI and card payments through a gateway — the free certificate is the right answer.
What happens at renewal
Nothing you have to do. AutoSSL checks daily and reissues roughly 30 days before expiry. It only fails if the domain stops resolving to the server, which is worth knowing if you ever move DNS: move the site first, then the DNS, or the certificate will lapse while the domain points somewhere else.
Common questions
→Read next
→Hosting for this
Plans that fit what you just read.
Every plan includes free SSL, free managed migration and a GST invoice.
→Get started
Hosting that does this for you.
Free managed migration, free SSL, and engineers who answer in under two minutes.