Cloud & Server Management

SSL Installation

We install SSL certificates and automate their renewal, then monitor expiry so nothing lapses unnoticed over a weekend. Chains, ciphers and redirects are tested from outside the server.

What SSL installation involves

An SSL (more accurately, TLS) certificate lets browsers connect to your site over HTTPS, encrypting traffic and proving the site is really yours. Without it, browsers show warnings, forms and logins are exposed, and many modern features refuse to work. SSL installation is getting the right certificate onto the server, configured correctly and renewed automatically.

Installation is the easy half. The problems usually come months later, when renewal fails silently, or when an incomplete certificate chain works on one browser but not on phones.

Signs you need help with SSL

  • Your site has shown a “not secure” or expired certificate warning at least once.
  • Some visitors see errors while others do not, often on older phones or API clients.
  • Pages load over HTTPS but images or scripts are blocked as mixed content.
  • An agency manages many client domains and tracks renewal dates in a spreadsheet.
  • A payment gateway, app store or partner API rejects your endpoint’s certificate.

What’s included

  • Choosing the right certificate: Let’s Encrypt for most sites, or commercial where a client or contract requires it.
  • Single-domain, multi-domain (SAN) or wildcard certificates, whichever keeps management simplest.
  • Installation on Nginx, Apache, a reverse proxy, a load balancer or a mail server.
  • Full certificate chain, modern TLS versions and strong cipher settings.
  • HTTP to HTTPS redirects and optional HSTS once everything is confirmed working.
  • Automated renewal with a test run, plus expiry monitoring and alerts.
  • An external check of the final configuration and a list of any mixed-content issues found.

How we do it

  1. Inventory the domains and subdomains that need coverage and where each is served from.
  2. Choose the validation method: HTTP for simple sites, DNS for wildcards or servers behind a proxy.
  3. Issue and install the certificates, configure TLS settings and redirects.
  4. Run a renewal dry run so we know renewal will actually work.
  5. Test from outside with browser and command-line tools, then add expiry monitoring.

Tools we use

Most installs use Let’s Encrypt through Certbot or the ACME support built into Traefik or Caddy. DNS validation works with providers such as Cloudflare, which is useful for wildcard certificates. For expiry monitoring we use Uptime Kuma or Prometheus exporters, so an alert fires well before a certificate lapses. When Cloudflare proxies your site, we also set its SSL mode correctly so traffic is encrypted all the way to your server, not just to Cloudflare.

What affects timeline and cost

One domain on one server is quick. More time is needed for many domains, certificates shared across several servers or load balancers, mail server certificates, legacy clients that need older protocols, or a site with a lot of mixed content to fix. Commercial certificates have their own fee from the issuing authority.

For agencies or businesses with many domains, we can also set up a simple overview of every certificate, its expiry date and where it is installed, so renewals are visible across the whole estate rather than tracked server by server.

Choosing the right certificate

The certificate type should follow how your domains are actually used. Picking the wrong one usually does not break anything immediately, but it makes renewal and management harder than it needs to be.

CertificateCoversGood fit for
Single domainOne hostname, often with its www versionA simple website or a single API endpoint
Multi-domain (SAN)A list of specific hostnamesA few related sites or services on one server
WildcardEvery subdomain at one level, such as *.example.comPlatforms that create customer subdomains or have many services
Commercial OV or EVAs above, with organisation checks by the issuerContracts, tenders or partners that require it

Wildcard certificates need DNS-based validation, which means the renewal process must be able to update DNS records automatically. We set this up with a scoped API token so the renewal tool can only touch what it needs, not your whole DNS account.

Whatever the type, we note in your documentation which certificate covers which hostnames, where it is installed and how it renews, so nobody has to rediscover it when something changes.

Common mistakes

  • Installing only the site certificate without the intermediate chain.
  • Never testing renewal, then discovering a firewall or redirect blocks it three months later.
  • Using Cloudflare’s Flexible mode, which leaves the connection to your server unencrypted.
  • Turning on HSTS with a long duration before every subdomain supports HTTPS.

Related: Domain Configuration, Cloudflare Setup and SSL Configuration in Cyber Security. See Cloud & Server Management, the cloud and server guide, or contact us.

Frequently asked questions

Is a free Let’s Encrypt certificate good enough?

For almost all websites and APIs, yes. The encryption is the same as paid certificates. Commercial certificates are mainly chosen for organisation validation or contractual requirements.

Do I need a wildcard certificate?

Only if you have many subdomains or create them frequently. Otherwise, individual or multi-domain certificates are simpler.

What happens when the certificate expires?

With automated renewal it should not. We also monitor expiry, so if renewal ever fails, someone is alerted with time to fix it.

Can you secure our mail server too?

Yes. Mail services use certificates as well, and they need to be renewed and reloaded just like the website’s.

Why does my site show a certificate error on some phones but not on my laptop?

That usually means the intermediate certificate chain is missing. Desktop browsers sometimes fill the gap themselves, while phones and API clients do not. Installing the full chain fixes it.

Talk to us about ssl installation

Let's Encrypt or commercial certificates installed with renewal automated.

Let's talk

Have something you need built, hosted or fixed?

Tell us what you are trying to do. If we are not the right people for it, we will say so.