How to Get and Install a Free SSL Certificate (Complete Guide)
SSL is free and automatic in 2026, yet sites still break over mixed content, expired certs and wrong redirects. Here is how HTTPS is issued, installed and kept renewed without you thinking about it.
HTTPS is no longer optional: browsers label HTTP sites as "not secure", search engines treat it as a ranking signal, and visitors will hesitate before typing a password into an insecure page. The good news is that a certificate costs nothing and takes minutes to install. This guide covers free SSL for your website, from validation to renewal to the errors that trip people up.
How certificate validation works
A Certificate Authority (CA) must prove you control the domain before it will issue a certificate. Two methods cover almost every case:
- HTTP-01 challenge. The CA fetches a specific file from
http://yourdomain/.well-known/acme-challenge/...over port 80. Your web server or panel places the file, validation succeeds, and the certificate is issued. Works for any domain pointed at your server. - DNS-01 challenge. The CA asks for a TXT record on your domain. It works even when the site is offline or behind a firewall, and it is how wildcard certificates (
*.yourdomain.com) are issued.
Let's Encrypt is the most widely used free CA, with certificates valid for 90 days and designed to be renewed automatically.
Installing in three paths
Managed panels. On cPanel, LiteSpeed or similar, open the SSL section and click "issue" or enable AutoSSL - it handles validation, installation and renewal for you. Command line. Certbot can obtain and install certificates for Nginx or Apache, and its renew cron runs twice daily. Your hosting provider. Many hosts issue and renew certificates automatically as part of the plan, which is the zero-effort path.
Forcing HTTPS the right way
Issuing the certificate is only half the job. You need every request redirected from HTTP to HTTPS, ideally with a single permanent 301 redirect rather than a chain. On Apache this is a small rewrite block in .htaccess; on Nginx it is a server block that returns 301 to the HTTPS host. Also make sure canonical URLs, sitemaps and internal links all use HTTPS, otherwise search engines see duplicate versions of every page.
Fixing mixed content
Mixed content happens when an HTTPS page loads assets over HTTP: images, scripts, stylesheets or embedded widgets. The browser blocks or warns on them, and the padlock may not appear. Fix by using relative URLs or protocol-relative paths, updating hardcoded http:// links in your theme or database, and replacing third-party embeds with HTTPS versions.
Renewal and monitoring
Free certificates last 90 days. Automatic renewal is standard, but set an expiry alert anyway - a broken renewal is the most common way sites lose HTTPS. Test renewal manually once (certbot renew --dry-run or the panel equivalent) and check that your web server actually picks up the new file. After renewal, verify the chain on an SSL checker: incomplete chains cause odd errors on some mobile browsers even when desktop looks fine.
Done correctly, you will never think about SSL again - which is exactly the point.
Ready to launch on NextyHost?
Every NextyHost web hosting plan includes a free auto-renewing SSL certificate.

