How to install a paid SSL certificate

Do you need a paid certificate?

Probably not. Webway issues a free Let's Encrypt certificate to every domain automatically (AutoSSL on cPanel, Let's Encrypt on DirectAdmin) once DNS points to the server, and renews it for you. It gives the same padlock and the same encryption as a paid one.

A paid certificate makes sense if you need:

  • Organisation (OV) or Extended Validation (EV): the certificate names your company after the issuer verifies it. Some banks and enterprise customers require this.
  • A wildcard covering every subdomain, if you have many.
  • A warranty, or a specific issuer your industry requires.

Webway doesn't sell paid certificates. Buy one from a certificate issuer or reseller, then install it as below.

Overview

  1. Generate a private key and a CSR (certificate signing request) in your control panel.
  2. Give the CSR to the certificate issuer and complete their validation.
  3. Receive the certificate and CA bundle.
  4. Install them in the control panel.

The private key never leaves your hosting account. Never email it or paste it into a ticket.

Step 1: Generate the key and CSR

cPanel

  1. Open Security → SSL/TLS.
  2. Click Certificate Signing Requests (CSR) → Generate, view, or delete SSL certificate signing requests.
  3. Under Key, choose Generate a new 2,048 bit key (or 4,096 if the issuer requires it).
  4. In Domains, enter your domain. For a wildcard, enter *.example.co.za. Add www.example.co.za on a second line if you want it covered and the issuer supports extra names.
  5. Fill in City, State (province), Country, Company and Company Division exactly as registered. The issuer checks these for OV/EV.
  6. Click Generate.
  7. Copy the whole Encoded CSR block, including the -----BEGIN and -----END lines.

DirectAdmin

  1. Open Account Manager → SSL/TLS Certificates.
  2. Choose Create A Certificate Request.
  3. Fill in the domain (or *.example.co.za for a wildcard), your organisation details and country, and choose a 2048-bit key.
  4. Click Save.
  5. Copy the whole CSR block shown.

The private key is stored in the panel automatically.

Step 2: Order and validate

  1. Buy the certificate from your issuer and paste the CSR when asked.
  2. Complete domain validation. The issuer offers a choice:
    • Email: they send a link to admin@, administrator@, webmaster@, hostmaster@ or postmaster@ your domain. Create that mailbox first if it doesn't exist.
    • File: upload a file they give you to a path under public_html/.well-known/. Keep the site reachable on plain http during this.
    • DNS: add a TXT or CNAME record they specify in your DNS zone.
  3. For OV/EV, complete the organisation checks. This takes days, not minutes.
  4. Download the issued files. You need the certificate (.crt or .pem) and the CA bundle (intermediate certificates, sometimes named ca-bundle.crt or chain.pem).

Step 3: Install

cPanel

  1. Open Security → SSL/TLS → Manage SSL sites.
  2. Under Install an SSL Website, choose the domain.
  3. Paste the certificate into Certificate (CRT). The private key should fill in automatically because you generated it here. If not, paste it from Private Keys.
  4. Paste the CA bundle into Certificate Authority Bundle (CABUNDLE).
  5. Click Install Certificate.

DirectAdmin

  1. Open Account Manager → SSL/TLS Certificates.
  2. Choose Paste a pre-generated certificate and key.
  3. Paste the private key and the certificate, each with its BEGIN and END lines.
  4. Save.
  5. Open CA Root Certificate, paste the CA bundle, and save.

Step 4: Check

  1. Open https://yourdomain.co.za in a private window. Click the padlock → certificate details. The issuer and organisation should match what you bought.
  2. Run an online SSL checker to confirm the chain is complete. A missing CA bundle shows as a chain error and warns on some phones.
  3. If you haven't already, force HTTPS. See How to force my website to use HTTPS.

Important: what happens when the paid certificate expires

On cPanel, AutoSSL is set to replace any non-AutoSSL certificate that expires or becomes invalid with a free Let's Encrypt one. Your site stays secure, but the OV/EV or wildcard details are gone.

So:

  • Diarise the expiry date. Renew with your issuer before it, and reinstall the new certificate using Step 3.
  • If AutoSSL has already swapped in a free certificate, install your renewed paid certificate over it. AutoSSL leaves a valid paid certificate alone.
  • Don't buy a paid certificate to "fix" an SSL problem. Fix the problem (usually DNS) and the free certificate issues itself. See Why does my website say "Not secure"?

On DirectAdmin, if automatic certificate provisioning is on for the domain, a free Let's Encrypt certificate can likewise take over when the paid one expires. Renew before expiry either way.

Problems

Problem Cause Fix
"The certificate does not match the private key" CSR generated elsewhere, or the key was deleted Install the key from the issuer's download if you generated the CSR with them, or reissue the certificate with a new CSR from the panel
Chain or "intermediate missing" warning CA bundle not installed Add the CA bundle (Step 3)
Padlock shows the old or free certificate Browser cache, or the install went to another domain Private window. Check Manage SSL sites shows your certificate against the right domain
Issuer's validation email never arrives The approver mailbox doesn't exist Create admin@yourdomain in the control panel and re-request the email
www shows a warning Certificate doesn't include www Reissue with both names, or set up a redirect from www to the bare domain

Did this answer it?