New Mexico Web Hosting - Frequently Asked Questions

How to install a Digital Certificate using cPanel


If you are a Web Hosting client of NewMexicoDomains and purchase an SSL Digital Certificatethrough us, we will install the Certificate for you and you can avoid the potential complexities, time and effort that are involved.

How to generate a Private Key using cPanel

Prior to generating a Private KEY file, a Dedicated IP address is required to install an SSL Certificate. If you do not have a Dedicated IP address, please contact a member of our sales team. Dedicated IP's are available for $1.25 per month per IP .

Now, assuming your Web Hosting account has a dedicated IP:

  • Log into your cPanel control panel
  • Click the SSL MANAGER icon ("SSL/TLS Manager")
  • Click the "Private Keys" icon
  • Page down to "Generate a New Key" and select the domain you wish to use with the SSL certificate.

We suggest you use "WWW" in the box preceding the domain name so that the Digital Certificate will point to "www.yourdomain.com" rather than "http://yourdomain.com". There are a number of reasons we recommend this.

The first is, if you're configuring the Certificate to work with a Shopping Cart, your customers will get "Certificate Mismatch" errors with the Certificate installed on the domain without the www, or you'll need to configure the secure part of your Cart to work without "www". Another reason we recommend installing your Digital Certificate pointing to "WWW" is that there is a potential problem with Google referred to as "canonicalization errors" when a website is configured to use "http://yourdomain.com". Do a search for "canonicalization errors", and you'll see what we mean.

If you want the SSL Certificate to be on a subdomain such as "cart.domain.com" be sure to create the subdomain in cPanel first, then enter the subdomain name in the box before generating the Key file.

  • After you have specified the domain you wish to use, click on the "Generate" button to create the Public Key file.

We suggest you copy this information to a TEXT file for safe keeping. It is possible to "Fetch" the KEY file from the server at a later time, however should the key file become corrupted or is lost, depending upon the type of SSL Certificate you have ordered, you maybe required to purchase a new SSL Certificate if you need to change information (Domain, etc.) at a later date. Please note that this private key file must be used with the specific SSL certificate that you plan on purchasing. This private key is secret and should not be given out. Also, there is no way to recover a private key file if it is lost.

Once you have Generated a Private Key, the next step is to create a "Certificate Signing Request". Follow the instructions below that describe:  "How to Generate a CSR."

If you need additional information on choosing a Digital Certificate, please visit:

http://www.newmexicodomains.com/domain_name_registration.html.

How to Generate a Certificate Signing Request - CSR

Prior to generating a CSR (Certificate Signing Request) your Hosting Plan must have a Dedicated IP and you must have previously generated a Private KEY file.

  • Log into your cPanel control panel
  • Click the SSL MANAGER icon ("MOD/SSL Manager")
  • Click on Certificate Signing Requests (CSR) (or "Generate, view, or delete SSL certificate signing requests")
  • For the HOST, choose the domain name that you made the Private KEY for. Once again, we recommend using "WWW" if you wish to install the certificate using www.

Please note that if you made a Private Key for "www.yourdomainname.com", you will need to include the "WWW" here. If the Private Key was generated for "cart.yourdomainnmame.com", you will need to enter that information instead. If you made the key for just "yourdomainname.com" without a "WWW", please be sure to enter it in that form.

If you are unable choose "www.yourdomainname.com" from the list, its likely that you did not configure the Private Key you generated previously with "WWW". If you require "WWW" for your Digital Certificate and you are unable to select "www.yourdomainname.com" from the list, please return to Generating a Private Key and start the process over again and enter "WWW" in the box preceding the domain name.

Next, complete the rest of the fields with the Required information.

  • The Country code Must be 2 digits - US, CA, IE, MX etc.
  • Enter your State or Territory in full; i.e., New Mexico (NOT NM)
  • Enter the City
  • Enter your Company name as you would like it to appear on the Digital Certificate. Should you want your company name and address to be in all UPPER CASE, for example, enter it in that manner here.
  • Where it asks for "Department or Division", this can be "Support" or "Sales" or any description you'd like.
  • Create a Password and Save It in a secure and accessible place. (It is NOT required for installation of the Digital Certificate). The pass phrase is used by Apache when it starts up to decipher your SSL private key.
  • Enter the Email address that the certificate should be sent to. Click on the Generate Button to generate the signing request.
  • If the process does not result in your CSR showing in Certificate Signing Requests on Server, Search for errors in how you completed the fields.

We strongly advise that you save this information in a TEXT file, using notepad or another text editor, NOT a Word Processing program that adds special characters and formatting.

This information information WILL be required when you purchase your SSL Certificate.

Once you have generated your CSR, collect your Private Key and CRT files, and follow the next set of instructions on how to install an SSL Certificate using Cpanel.






How to install an SSL Certificate using Cpanel

Before you can install an SSL Certificate you must first have completed the steps for "How to Generate a Private Key File" and "How to Generate a CSR (Certificate Signing Request)".

  • Log into your cPanel control panel.
  • Click on MOD/SSL Manager icon, and then choose Certificates (CRT)
  • Choose the domain you wish to install from the drop down menu at the top


NOTE: If you are REPLACING an existing Digital Certificate, you must uninstall the old certificate first by clicking Delete from the Host drop down button.

  • In the box, you will paste the CRT file that was emailed to you from your SSL Certificate provider.
  • The KEY file (second section) will automatically display. If it does not, you can click FETCH and it will import. Problems? Then you will need to paste a copy of your Private KEY file that you saved into this section.

Click the "Do It" button (or "Install Certificate") and wait for the confirmation.

Your SSL Certificate is now installed. Test it by opening https://www.yourdomainname.com substituting your actual domain name, and removing the "WWW" if you opted not to use www in your certificate.

Note that Certain Digital Certificates require an Apache re-start. If your browser does not display the Secure symbol (most often a padlock icon) please enter a support ticket and we will re-start Apache for you.