Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/Troubleshooting/Troubleshoot TLS certificate provisioning

Troubleshoot TLS certificate provisioning

LAST UPDATED

3 months ago

    WP Cloud normally provisions and renews TLS certificates automatically after a domain points to the platform. If a certificate is missing or delayed, inspect the exact hostname, correct its DNS or proxy configuration, and then retry provisioning.

    Inspect the hostname

    Use the Fetch SSL Certificate Information endpoint separately for every affected hostname:

    curl --fail-with-body --silent --show-error \
      --request POST \
      --header "Auth: ${WP_CLOUD_API_KEY}" \
      "https://atomic-api.wordpress.com/api/v1.0/ssl-info/${WP_CLOUD_DOMAIN}"Code language: JavaScript (javascript)

    The response can include:

    FieldMeaning
    acme_certificate_id or ssl_certificate_idA certificate identifier when issuance succeeded. The field used can vary.
    validation_expirationThe platform’s validation window, not the certificate’s expiration date.
    optionsPlatform behaviors such as HTTPS redirects and HTTP Strict Transport Security (HSTS).
    certificate_expiration_dateWhen the issued certificate expires.
    ca_providerThe certificate authority, such as letsencrypt or google.
    authz_uriAn LE authorization URL that can provide details about a validation attempt.
    broken_recordThe reason provisioning failed and its retry state.

    The broken_record object is the main starting point for a failed attempt:

    • reason gives the high-level cause, such as not hosted here or authorization failure.
    • last_error records the last failed attempt.
    • retry_date records the next scheduled attempt.
    • failcount records the number of failures for the hostname.

    If ssl-info returns Not Found or Site not found, WP Cloud does not recognize that hostname as a domain or alias on the site. Add the missing hostname, such as www when only the apex domain exists, then inspect it again.

    Check DNS records

    Certificate provisioning uses the ACME HTTP-01 challenge. The certificate authority must be able to reach the exact hostname on WP Cloud over HTTP.

    A records

    Check the apex domain and www separately when both are attached to the site:

    dig A example.com +short
    dig A www.example.com +shortCode language: CSS (css)

    An A record that points elsewhere can appear in broken_record.reason as not hosted here. Remove conflicting records, wait for the correct records to propagate, and check the hostname again.

    AAAA records

    If a hostname publishes an AAAA record that does not route IPv6 traffic to WP Cloud, the certificate authority can attempt validation at that address and fail:

    dig AAAA example.com +shortCode language: CSS (css)

    Remove or correct a conflicting AAAA record, then wait for DNS propagation.

    CAA records

    Certification Authority Authorization (CAA) records restrict which certificate authorities can issue for a domain:

    dig +nocmd example.com CAA +noall +answerCode language: CSS (css)

    CAA policy must allow the provider WP Cloud is using. Allow letsencrypt.org for LE and pki.goog for GTS, or remove a conflicting restriction when that matches the domain owner’s policy.

    DNSSEC

    Broken Domain Name System Security Extensions (DNSSEC) configuration can prevent validation. Correct the delegation and DNSSEC records with the registrar or DNS provider, or disable DNSSEC until it is configured correctly.

    For GTS-specific failures, Google Public CA DNS debugging describes its CAA and global DNS consistency checks.

    Inspect a Let’s Encrypt authorization

    For an LE validation failure, authz_uri can identify the address and challenge URL used by the certificate authority. It may be absent, and it does not apply to a GTS certificate.

    Retrieve the returned URL with a browser or curl:

    curl --fail-with-body --silent --show-error "${AUTHZ_URI}"Code language: JavaScript (javascript)

    In the authorization JSON, check:

    • status; invalid means validation failed;
    • challenges[].error.detail for the reported cause; and
    • challenges[].validationRecord[].addressesResolved and addressUsed to see which address received the HTTP-01 request.

    For example, if addressesResolved contains the expected WP Cloud IPv4 addresses and an unrelated IPv6 address, and addressUsed shows that IPv6 address, correct or remove the conflicting AAAA record before retrying.

    Let’s Debug can perform another public LE validation check. The Qualys SSL Server Test reports the certificate and TLS configuration visible to clients.

    Check Cloudflare and other proxies

    A proxy can prevent the certificate authority from reaching WP Cloud’s HTTP-01 challenge response. Avoid proxying WP Cloud domains when possible. If a site uses Cloudflare, follow the recommended Cloudflare configuration and check its DNS and proxy state.

    Retry certificate provisioning

    After correcting every reported DNS or configuration problem, use the Retry SSL Provisioning endpoint for the affected hostname:

    curl --fail-with-body --silent --show-error \
      --request POST \
      --header "Auth: ${WP_CLOUD_API_KEY}" \
      "https://atomic-api.wordpress.com/api/v1.0/ssl-retry/${WP_CLOUD_DOMAIN}"Code language: JavaScript (javascript)

    An accepted retry returns:

    {
      "message": "OK",
      "data": {
        "queued": true
      }
    }Code language: JSON / JSON with Comments (json)

    Retry example.com and www.example.com separately when both are affected. Do not repeatedly queue retries while DNS is incorrect or still propagating; additional failures can increase retry backoff and can trigger API rate limits.

    Previous Troubleshoot PDF thumbnail generation

    Related Guides

    • Troubleshoot Page and Edge Cache

      Diagnose Page Cache and Edge Cache misses using response headers, cookies, cache controls, bypass code,…

      5 Min.

      READ

    • Troubleshoot HTTP 429 and 599 errors

      Partner support teams can distinguish visitor-facing HTTP 429 responses from WP Cloud HTTP 599 records,…

      6 Min.

      READ

    • WP Cloud HTTP status codes

      Understand HTTP status codes reserved for WP Cloud suspension, maintenance, security, and rate-limiting responses.

      1 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications