# Free SSL Can Lead to HUGE Headaches

**URL:** <https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645>\
**Category:** Help\
**Created:** [October 1, 2018, 5:32pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645 "2018-10-01T17:32:39Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 5:32pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/1 "2018-10-01T17:32:39Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [saliu.com](http://saliu.com)

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is: [ipage.com](http://ipage.com)

I can login to a root shell on my machine (yes or no, or I don’t know): no

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): yes

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 5:33pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/2 "2018-10-01T17:33:23Z")

</div>

Free SSL Can Lead to HUGE Headaches

In July of 2018, my web host, **[iPage.com](http://iPage.com)** , offered me free SSL via Let’s Encrypt. I accepted the “challenge” and I went through all that process. I succeeded in implementing SSL on my site **[saliu.com](http://saliu.com)** in a couple of hours.

For the most part, Let’s Encrypt SSL worked correctly. There were issues, however. Out of the blue, pages on my site were rendered “not safe” by browsers! The issue was: \*“The [saliu.com](http://saliu.com) site tries to steal the SSL certificate of _.bizland.com”_ . What?

Then, the warnings disappeared. Then, they reappeared randomly. In any event, I accepted the infrequent issues. I hoped my web host would resolve the issue permanently. They assured me of that in an email.

The worst happened on September 29, 2018. The browsers informed me that the free Let’s Encrypt SSL certificate was valid from 7/1/2018 to 9/29/2018! What? Nobody informed me about an expiration date!

I contacted my web host several times. They always promised me the SSL issues on my site will be timely resolved. Time has passed, and my site looks now much worse in browsers than when it was simple (and still secure) **http**.

What’s going on, folks? This is a grave issue with severe legal implications. I’ve lost business and get legal threats from customers. They can’t download my software. They are scared to death to access my Web site!

Thank you for any assistance.

Ion Saliu,

Webmaster At-Large

_“A good man is an axiomatic man; an axiomatic man is a happy man. Be axiomatic!”_

---

<div class="post-metadata">

**Author:** ![tdelmas](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/tdelmas/32/1866_2.png) [@tdelmas](https://community.letsencrypt.org/u/tdelmas)\
**Post date:** [October 1, 2018, 5:41pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/3 "2018-10-01T17:41:35Z")

</div>

> [@Ion\_Saliu](#):
>
> Out of the blue, pages on my site were rendered “not safe” by browsers! The issue was: \*“The [saliu.com](http://saliu.com) site tries to steal the SSL certificate of _.bizland.com”_ . What?

That was probably a problem with your hosting provider: the website presented the wrong certificate to your browser.

> [@Ion\_Saliu](#):
>
> Nobody informed me about an expiration date!

If your hosting provider handle the creation of the certificate it should handle the renewal too. All certificates, free or not, expired one day. (The advantage on Let's Encrypt it that the renewal can be automated)

> [@Ion\_Saliu](#):
>
> than when it was simple (and still secure) **http**.

**http** was and will never be secure. With http you can't be sure that the website you send to your visitor will be the one they will see: sometimes ads are inserted without your knowledge, sometimes tracking cookies. And if your visitors have to fill forms, all data they submit can be read, or modified by anyone on the network! An interesting read: [Troy Hunt: Here's Why Your Static Website Needs HTTPS](https://www.troyhunt.com/heres-why-your-static-website-needs-https/)

> [@Ion\_Saliu](#):
>
> Thank you for any assistance.

Could you provide a screenshot of how you ask for https/certificate on your hosting provider?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 1, 2018, 5:50pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/4 "2018-10-01T17:50:01Z")

</div>

> [@Ion\_Saliu](#):
>
> In July of 2018, my web host, **[iPage.com](http://iPage.com)** , offered me free SSL via Let’s Encrypt. I accepted the “challenge” and I went through all that process. I succeeded in implementing SSL on my site **[saliu.com](http://saliu.com)** in a couple of hours.

So you needed to **manually** implement the challenge? There wasn't just a button to press in your control panel? Because most of the time, a hoster which implements Let's Encrypt does so by providing a plugin in their control panel to take care of _everything_. Unfortunately, there are a lot of hosters not implementing such an automated system. If your hoster is one of the latter, you should change hosting provider to one which _does_ provide automated implementation.

See the [Web Hosting who support Let’s Encrypt](https://community.letsencrypt.org/t/web-hosting-who-support-lets-encrypt/6920) thread for more info.

> [@Ion\_Saliu](#):
>
> There were issues, however. Out of the blue, pages on my site were rendered “not safe” by browsers! The issue was: \*“The [saliu.com](http://saliu.com) site tries to steal the SSL certificate of _.bizland.com”_ . What?

That's not something Let's Encrypt can prevent nor does Let's Encrypts certificate **itself** cause such a thing. Only your hoster can is to blame.

> [@Ion\_Saliu](#):
>
> The worst happened on September 29, 2018. The browsers informed me that the free Let’s Encrypt SSL certificate was valid from 7/1/2018 to 9/29/2018! What? Nobody informed me about an expiration date!

See [FAQ - Let's Encrypt](https://letsencrypt.org/docs/faq/#what-is-the-lifetime-for-let-s-encrypt-certificates-for-how-long-are-they-valid)

> **What is the lifetime for Let’s Encrypt certificates? For how long are they valid?**  
> Our certificates are valid for 90 days. You can read about why [here](https://letsencrypt.org/2015/11/09/why-90-days.html).
> 
> There is no way to adjust this, there are no exceptions. We recommend automatically renewing your certificates every 60 days.

> [@Ion\_Saliu](#):
>
> What’s going on, folks?

I guess you chose for a sub-optimal hosting provider. Unfortunately, this could be just the only thing they don't implement implement and you couldn't have known this before.

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 6:26pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/5 "2018-10-01T18:26:06Z")

</div>

Osiris, Brother and Husband of Isis –

Axiomatic One:

You might not live in an English-speaking country, but that’s OK. Perhaps I should have made myself clearer.

1. The free Let’s Encrypt SSL certificate for my site was implemented by my web host. The only thing I did manually was the 301 redirect to https I added to my htaccess file.

2. As I said, the free SSL worked properly for the most part. The infrequent issues were real though. My web host didn’t know how to solve the problem.

3. Apparently, my web host **[iPage.com](http://iPage.com)** did NOT know about an expiration date. Obviously, they should have taken care of the renewal. Looks like they still don’t know how to renew the free Let’s Encrypt SSL certificate. That’s what causes the severe problems now. The Control Panel still offers the free Let’s Encrypt SSL service to their customers!

4. You sez: _“… you should change hosting provider…”_  
Are you serious? Changing hosting is a gigantic headache leading to serious business losses, visitor frustration, ranking hits, etc. Besides, my current host is pretty good. My site is pretty fast, uptime is great, never hit by malware or hack attacks. My previous host, GoDaddy, was a real technical nightmare!

I want to thank you for your response. I learned useful things from it.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [October 1, 2018, 7:21pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/6 "2018-10-01T19:21:14Z")

</div>

Hi @Ion_Saliu

> [@Ion\_Saliu](#):
>
> My domain is: [saliu.com](http://saliu.com)

> [@Ion\_Saliu](#):
>
> My hosting provider, if applicable, is: [ipage.com](http://ipage.com)

using Google

`letsencrypt site:ipage.com`

is curious. There

[https://www.ipage.com/ssl-certificate](https://www.ipage.com/ssl-certificate)

is no free Letsencrypt certificate offered. Free is \*.ipage.com, but if you want to encrypt your own domain, you have to pay a Comodo-certificate.

A blog entry (Jan 17, 2018)

[http://ipage.com/blog/ssl-websecurity/](http://ipage.com/blog/ssl-websecurity/)

is "very low". Something like

> If you want to take payments through your site, you must buy an SSL certificate.

is wrong. And the blog doesn't use https - October 2018.

So it looks that iPage doesn't really want to offer Letsencrypt certificates with shared hosting.

The features page

[https://www.ipage.com/web-hosting](https://www.ipage.com/web-hosting)

There is the same.

> Free SSL Certificate

completely unclear. Perhaps you should ask the support if this works only with \*.ipage.com.

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 8:21pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/7 "2018-10-01T20:21:35Z")

</div>

JuergenAuer

Axiomatic One:

Thank you for your insightful response.

Curiously, after reading your reply, the iPage free SSL worked on my [saliu.com](http://saliu.com) site until 9/29/2018 (the expiration date). Again, some errors popped up randomly, but not frequently. There was a reference to a \*.bizland.com (or something like that) — as if my site tried to “steal” the SSL certificate issued to that _bizland_ .

The iPage tech support keeps emailing me that they are working on it. They promised a “timely” solution, but would-be visitors to my site still see that terrible warning (Chrome is devilish in this regard)!

I even asked iPage if the “free SSL” was simply a bait. That is, after you commit effort in changing to https, you don’t want to go back to http. So, they somehow force you to pay for an SSL certificate (they offer Comodo). I told them if it was the case and I would consider buying a so-called “wild SSL” (one domain with multiple subdomains). No response yet.

Is iPage still a supported host by you? I didn’t seem to find that name on your lists. Did _Let’s Encrypt_ revoke the free SSL certificate issued to _iPage_ ?

In any event, to ameliorate the damage, I removed the ‘301 redirect to https’ from my htaccess file. But there are still inbound links pointing to https pages on my site…

Ion Saliu,

Webmaster At-Large

_“A good man is an axiomatic man; an axiomatic man is a happy man. Be axiomatic!”_

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 8:29pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/8 "2018-10-01T20:29:54Z")

</div>

On the other hand, I sense Google and other browser companies are going to suffer legal trouble. Google Chrome especially is liable with that **‘not secure’** warning in front of all _http_ URLs. The legally correct message should read: **‘not encrypted’.** Better still, the browsers should just show an _ **i** _ in front of the page (more like Firefox). The _https_ URLs get a lot of leverage by displaying the lock.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [October 1, 2018, 8:33pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/9 "2018-10-01T20:33:57Z")

</div>

> [@Ion\_Saliu](#):
>
> the iPage free SSL worked on my [saliu.com](http://saliu.com) site until 9/29/2018 (the expiration date).

Every certificate has an expiration day. Letsencrypt certificates are 90 days valide.

So if a company installs a Letsencrypt certificate without a renew job, this is completely bad and terrible. There is no excuse.

> [@Ion\_Saliu](#):
>
> Is iPage still a supported host by you? I didn’t seem to find that name on your lists.

What do you mean? I am a freelancer from Berlin, I have my own service.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [October 1, 2018, 8:34pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/10 "2018-10-01T20:34:04Z")

</div>

> [@Ion\_Saliu](#):
>
> Is iPage still a supported host by you? I didn’t seem to find that name on your lists. Did _Let’s Encrypt_ revoke the free SSL certificate issued to _iPage_ ?

Hosting providers don't need a contract or agreement with Let's Encrypt in order to obtain and use Let's Encrypt certificates.

There is a list at

[https://community.letsencrypt.org/t/web-hosting-who-support-lets-encrypt/6920/608](https://community.letsencrypt.org/t/web-hosting-who-support-lets-encrypt/6920/608)

but this is simply informational and intended to help users choose hosting providers who are known to support Let's Encrypt. It's not a list of entities that Let's Encrypt has relationships with.

Let's Encrypt did not revoke certificates for your site. If it had, the error users saw would be totally different. Instead, your certificates expired normally on the expected schedule. Your hosting provider apparently failed to renew them. If the hosting provider obtains certificates for customers, renewing those certificates is also the hosting provider's responsibility.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 1, 2018, 8:45pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/11 "2018-10-01T20:45:50Z")

</div>

> [@Ion\_Saliu](#):
>
> (…) I would consider buying a so-called “wild SSL” (one domain with multiple subdomains).

You can get a wildcard certificate from Let's Encrypt for free.

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 8:47pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/12 "2018-10-01T20:47:05Z")

</div>

tdelmas

Axiomatic One:

Sorry for the delay. I finally decided to take a screenshot. This is from my Control Panel. I open the Security tab for my domain. I have the option to Enable or Disable the _Let’s Encrypt Free SSL._ Hopefully, I’ll be able to download or show here the screenshot:

![](https://global.discourse-cdn.com/letsencrypt/original/3X/4/0/40e34a90a30834a7e040d848b5dfa04dde09baf3.gif)

As you can see, I enabled _Let’s Encrypt Free SSL._ The feature worked most of the time until September 29, 2018, when the certificate expired. I also added the ‘301 redirect to https’ to my htaccess file.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 1, 2018, 8:50pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/13 "2018-10-01T20:50:38Z")

</div>

> [@Ion\_Saliu](#):
>
> As you can see, I enabled _Let’s Encrypt Free SSL._

With just that one press on a button? Because earlier you said:

> [@Ion\_Saliu](#):
>
> I succeeded in implementing SSL on my site (…) **in a couple of hours**.

Pressing a single button normally doesn't take a couple of hours in my experience.

I'm still trying to get my head around on how your hosting provider actually provides the Let's Encrypt option. Although I agree the screenshot would suggest the hosting provider should be responsible for renewing the certificate.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [October 1, 2018, 8:52pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/14 "2018-10-01T20:52:58Z")

</div>

> [@Ion\_Saliu](#):
>
> As you can see, I enabled _Let’s Encrypt Free SSL._

Disable it. Wait one minute.

Enable it again.

Are there other things you've changed? Or did you delete some files?

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 8:58pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/15 "2018-10-01T20:58:51Z")

</div>

Osiris

No offense, axiomatic one. Methinks linguistics brings about some misunderstanding. Also, I should have been clearer, as per my first reply.

Yes, just a press of a button… it was that easy! Then, a few more minutes to edit my htaccess file by adding the ‘301 redirect to https’. It was pretty fast.

_ **Then, I waited a couple of hours for SSL to take effect.** _

That’s what I meant. I checked first after about half an hour but https was not in effect.

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 9:06pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/16 "2018-10-01T21:06:38Z")

</div>

JuergenAuer

Axiomatic One:

I thought you _was_ an employee of _Let’s Encrypt_ . This is my first day here.

I did what you said a few times. I enabled, then disabled… and again… The problem didn’t go away. The tech support did also the same thing.

\*_The iPage tech support informed me that the problem I reported affected ALL domains that enabled Let’s Encrypt Free SSL._

The curious thing is somebody, or the system, did disable the _Let’s Encrypt Free SSL._ It wasn’t me. I don’t know who did it and why. I’ve had no answer from my host.

Now, I uploaded the old htaccess , the file my site had before this https debacle and headache.

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 9:14pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/17 "2018-10-01T21:14:08Z")

</div>

> [@Osiris](#):
>
> You can get a wildcard certificate from Let’s Encrypt for free.

Osiris

Axiomatic One:

_“You can get a wildcard certificate from Let’s Encrypt for free.”_

My webhost is strict about SSL certificates. The host states: _“Dedicated SSL certificates” do not work with a domain with multiple subdomains,_ like my domain. The host accepts only the form of _Let’s Encrypt_ that I described here. Dedicated for them means from outside the hosting.

They offer a paid-for Comodo SSL and it’s possible they want me to go there. The “freebie” I was offered was bait! The only option I have with multiple subdomains is the host’s Comodo.

---

<div class="post-metadata">

**Author:** ![jared.m](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jared.m/32/17871_2.png) [@jared.m](https://community.letsencrypt.org/u/jared.m)\
**Post date:** [October 1, 2018, 9:24pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/18 "2018-10-01T21:24:40Z")

</div>

> [@Ion\_Saliu](#):
>
> They offer a paid-for Comodo SSL and it’s possible they want me to go there. The “freebie” I was offered was bait! The only option I have with multiple subdomains is the host’s Comodo.

That's a money-making tactic employed by your hosting provider. Let's Encrypt has no such restriction. Multiple domain and wildcard certificates are also free.

---

<div class="post-metadata">

**Author:** ![Ion\_Saliu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ion_saliu/32/26494_2.png) [@Ion\_Saliu](https://community.letsencrypt.org/u/Ion_Saliu)\
**Post date:** [October 1, 2018, 9:36pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/19 "2018-10-01T21:36:39Z")

</div>

jared.m

Axiomatic One:

_“That’s a money-making tactic employed by your hosting provider. Let’s Encrypt has no such restriction. Multiple domain and wildcard certificates are also free.”_

Mea culpa again! I wasn’t clear enough. The _Let’s Encrypt Free SSL_ for my domain was a “wild card” type. It worked with ALL my subdomains. Also, the subdomains experienced the same infrequent issues I described before. The free SSL “died” on all domains at the same time on 9/29/2018.

The webhost either doesn’t know how to do automatic renewals, OR they used the freebie as bait. Right at this moment, I go in the direction of paying a hundred bucks for a Comodo. This freebie threw me into a deep nightmare!

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [October 1, 2018, 10:26pm UTC](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645/20 "2018-10-01T22:26:45Z")

</div>

Hi @Ion_Saliu,

> [@Ion\_Saliu](#):
>
> The webhost either doesn’t know how to do automatic renewals, OR they used the freebie as bait.

If any of those statements are true, the answer is that you deserve a better hosting company and it is time to move on. Your certificate expired 2 days ago and you only get from ipage 'it will be solved in a timely manner...' that is unacceptable.

Anyway, I doubt they are using the freebie as bait because of one of the core features they are offering with their hosting is a Free SSL Certificate.

> [@Ion\_Saliu](#):
>
> I go in the direction of paying a hundred bucks for a Comodo.

I suppose that you could get a better deal if your hosting company is a Comodo's reseller but a Wilcard Certificate from Comdo costs $199/yr [Cheap Wildcard SSL Certificate, Comodo Wildcard SSL, Wildcard Certificate](https://comodosslstore.com/comodo-wildcard-ssl.aspx) also, keep in mind that usually, a wildcard certificate covers ONLY subdomains, that is, it covers `*.saliu.com` (`www.saliu.com, webmail.saliu.com, whatever.saliu.com, etc.`) but it doesn't cover `saliu.com` nor `www.subdomain.saliu.com` so before buy a certificate, you should double check whether it covers `*.saliu.com` AND `saliu.com` OR only `*.saliu.com`. Anyway, if your hosting company doesn't know how to renew and apply a free certificate I don't know how they would be able to apply any kind of certificate.

> [@Ion\_Saliu](#):
>
> This freebie threw me into a deep nightmare!

I would say, My hosting company doesn't know how to manage the services they are offering and this is threwing me into a deep nightmare.

You could share this thread with you hosting support and if they are having issues to renew the certificate they could ask here for some help.

I hope your hosting company can resolve this issue as soon as possible.

Good luck,  
sahsanu

[Next page](https://community.letsencrypt.org/t/free-ssl-can-lead-to-huge-headaches/73645.md?page=2)
