Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/Sites/Domains/TLS certificates

TLS certificates

LAST UPDATED

3 months ago

    WP Cloud provisions, installs, and renews Transport Layer Security (TLS) certificates—often called SSL certificates—for a site’s domains. Provisioning normally starts after a domain or alias is added and its DNS points to WP Cloud.

    Note: SSL and TLS are both cryptographic protocols, and TLS is an evolution of SSL. TLS is sometimes referred to as “SSL,” as in “SSL certificate,” even though all versions of the SSL protocol are disabled on WP Cloud.

    How certificate provisioning works

    WP Cloud provisions certificates through Let’s Encrypt (LE) and Google Trust Services (GTS). Renewals are automatic and require no routine partner maintenance.

    Certificate provisioning uses the ACME HTTP-01 challenge. Each hostname must resolve to WP Cloud and allow the certificate authority to retrieve its challenge over HTTP.

    example.com and www.example.com are validated and managed independently. One hostname can have a certificate while another reports an error.

    Failed attempts are requeued automatically. Consecutive failures increase the delay before the next attempt, and the retry_date returned by the API can move farther into the future. Correct the DNS or configuration error before requesting an immediate retry.

    When LE itself is unavailable, check the Let’s Encrypt service status before changing the site’s DNS.

    Inspect certificate information

    Use the Fetch SSL Certificate Information endpoint separately for every hostname you need to inspect. The response can identify the certificate, certificate authority, expiration, validation state, HTTPS behavior, and any failed provisioning attempt.

    The ca_provider field identifies letsencrypt or google. A browser’s certificate details also show the issuer organization as Let’s Encrypt or Google Trust Services.

    On macOS or another system with OpenSSL, inspect the issuer from the command line:

    echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -issuerCode language: JavaScript (javascript)

    Certificate chains and issuer common names can change. Use the issuer organization and the API’s provider field rather than depending on a specific common name in an integration.

    TLS compatibility

    During the TLS handshake, the server and client select the strongest mutually supported cipher from the server’s preferred list. WP Cloud disables TLS 1.0 and TLS 1.1 but retains some TLS 1.2 ciphers for compatibility with older browsers and devices.

    A scanner can flag one of those compatible ciphers even when modern clients negotiate a stronger choice. Evaluate a scanner finding in the context of protocol version, negotiation order, browser compatibility, and the actual exploit described by the report.

    If a certificate is missing, delayed, or failing validation, use Troubleshoot TLS certificate provisioning.

    Previous Domain verification records
    Next Manage custom TLS certificates

    Related Guides

    • Manage site domains and aliases

      Manage primary and secondary WP Cloud site domains, control alias canonicalization, retrieve suggested DNS addresses,…

      4 Min.

      READ

    • Domain verification records

      Publish WP Cloud DNS TXT verification records when a domain is already assigned to a…

      2 Min.

      READ

    • Manage custom TLS certificates

      Validate, stage, activate, renew, deactivate, and remove partner-supplied TLS certificates safely.

      3 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications