Current Plesk SSL controls
Plesk 9 is obsolete: manage a website certificate in Plesk Obsidian under Websites & Domains and SSL/TLS Certificates
Do not use old Plesk 9 paths or edit server certificate files directly. Open the correct domain, select SSL/TLS Certificates and use SSL It! or Advanced Settings to issue, upload, assign, renew or inspect the certificate.
Where are certificate controls now?
- 1Open Plesk
Use the hosting service in the UKC Client Area to reach the assigned server securely.
- 2Choose the domain
In Websites & Domains find the exact website you want to secure.
- 3Open SSL/TLS Certificates
Review the current security status, certificate authority, covered names and expiry.
- 4Choose the required action
Use Let’s Encrypt, upload an existing certificate or open Advanced Settings for CSR and repository controls.
Which certificate route should you use?
Free Let’s Encrypt
Issue a trusted certificate for the main domain and required www, webmail or mail names that point correctly to the server.
Existing certificate
Upload the certificate, private key and chain carefully. A mismatched key cannot be fixed by renaming files.
Certificate signing request
Create a CSR in Advanced Settings when an external certificate authority requires one.
Parked-domain SSL
A parked domain uses a separate paid Domain Parking SSL add-on that is provisioned after purchase, usually within minutes.
What should you do after installation?
Test the exact HTTPS hostnames, confirm the browser shows the intended certificate and fix mixed-content errors. Only then enable a permanent HTTP-to-HTTPS redirect. Enable HSTS only after every required hostname and resource works securely, because HSTS can make a broken HTTPS configuration harder for visitors to bypass.
SSL questions
Why did Let’s Encrypt fail?
The requested hostname must resolve to the hosting server and be reachable for validation. Check DNS, redirects and selected names.
Why is the wrong certificate displayed?
Confirm the certificate is assigned to the correct domain and that the hostname reaches the expected server. CDN or proxy settings can also terminate HTTPS elsewhere.
Should I use a self-signed certificate?
Not for a public customer website. It encrypts the connection but browsers do not trust its identity and will show a warning.
Can I edit certificate files over SSH?
Customers should use Plesk controls. Direct server changes can be overwritten, expose private keys or affect other services.
Use current Plesk
Open SSL/TLS Certificates for the exact domain
Test HTTPS before enabling redirects or HSTS.