# Shared Hosting?

**URL:** <https://community.letsencrypt.org/t/shared-hosting/384>\
**Category:** Server\
**Created:** [August 21, 2015, 8:23am UTC](https://community.letsencrypt.org/t/shared-hosting/384 "2015-08-21T08:23:29Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![carstorm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/carstorm/32/252_2.png) [@carstorm](https://community.letsencrypt.org/u/carstorm)\
**Post date:** [August 21, 2015, 8:23am UTC](https://community.letsencrypt.org/t/shared-hosting/384/1 "2015-08-21T08:23:29Z")

</div>

Will certs provided by let’s encrypt work on shared web host? Can users with cPanel get a cert themselves or will the hosting company have to set it up?

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [August 21, 2015, 5:26pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/2 "2015-08-21T17:26:39Z")

</div>

Hi @carstorm,

There's another thread here where we're talking about cPanel compatibility, which was at

> [@cPanel and LiteSpeed Enterprise](https://community.letsencrypt.org/t/cpanel-and-litespeed-enterprise/77):
>
> H…

In general Let's Encrypt will often require some level of support from a shared hosting provider, and we hope to talk to many of the hosting providers to make sure that they take whatever steps are necessary to achieve that support. There may be some configurations in which hosting providers already allow users to deploy certs without the providers' intervention; in those configurations it may be possible for a shared hosting user to get a Let's Encrypt cert and install it manually.

It will almost always require the provider's assistance to allow the process to be automated on the provider's infrastructure (for example, installing the cert automatically or renewing the cert automatically).

---

<div class="post-metadata">

**Author:** ![carstorm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/carstorm/32/252_2.png) [@carstorm](https://community.letsencrypt.org/u/carstorm)\
**Post date:** [August 21, 2015, 10:03pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/3 "2015-08-21T22:03:41Z")

</div>

Ok, thank you for the quick response. Among the hosting providers be sure to include hosting24.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [August 24, 2015, 6:25pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/4 "2015-08-24T18:25:57Z")

</div>

I’m going to be going to some hosting industry events to try to drum up interest and contacts, but in general I think we need the hosting providers to contact us rather than the other way around. If anyone here is a customer or employee of a hosting provider that might be interested in Let’s Encrypt integration but hasn’t figured out what to do, please encourage the provider to get in touch with us!

---

<div class="post-metadata">

**Author:** ![Archer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/archer/32/142_2.png) [@Archer](https://community.letsencrypt.org/u/Archer)\
**Post date:** [August 25, 2015, 4:30pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/5 "2015-08-25T16:30:16Z")

</div>

Hi Schoen!

What’s the preferred point of contact for any hosting companies to reach out to Let’s Encrypt for integration?

–…Archer

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [August 25, 2015, 6:45pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/6 "2015-08-25T18:45:15Z")

</div>

I’m happy for people to contact me via my username here at [eff.org](http://eff.org). That’s one option. You can also post a request for contact on this support forum, or e-mail the general Let’s Encrypt inquiries e-mail address on the Let’s Encrypt web site.

---

<div class="post-metadata">

**Author:** ![7skiestech](https://avatars.discourse-cdn.com/v4/letter/7/a87d85/32.png) [@7skiestech](https://community.letsencrypt.org/u/7skiestech)\
**Post date:** [August 27, 2015, 9:32pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/7 "2015-08-27T21:32:41Z")

</div>

I’m on shared hosting as well. I will totally reach out to my provider, share the [http://letsencrypt.org](http://letsencrypt.org) link with them and ask them to contact you. But what exactly should I be asking for them to do? Thank you.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [August 28, 2015, 7:06pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/8 "2015-08-28T19:06:00Z")

</div>

It depends on what you want from them; different people have different expectations of their hosting providers.

Some people would like to see the Let’s Encrypt client preinstalled in hosting provider OS images or installs, some people would like to see it integrate with different kinds of management UI, some people would like to see the hosting provider go out and automatically obtain the certificates for the users. I think a lot depends on the kind of hosting and the kind of service that the customers are receiving.

---

<div class="post-metadata">

**Author:** ![7skiestech](https://avatars.discourse-cdn.com/v4/letter/7/a87d85/32.png) [@7skiestech](https://community.letsencrypt.org/u/7skiestech)\
**Post date:** [September 23, 2015, 3:03pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/9 "2015-09-23T15:03:24Z")

</div>

I reached out to several web hosts I, or clients, have websites on. Have you heard from a decent number of web hosts who plan to support letting their shared hosting customers make use of Let’s Encrypt?

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [September 25, 2015, 9:01pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/10 "2015-09-25T21:01:31Z")

</div>

Yes, there seems to be quite a bit of interest in that.

---

<div class="post-metadata">

**Author:** ![solvik](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/solvik/32/954_2.png) [@solvik](https://community.letsencrypt.org/u/solvik)\
**Post date:** [October 20, 2015, 10:18am UTC](https://community.letsencrypt.org/t/shared-hosting/384/11 "2015-10-20T10:18:13Z")

</div>

Hi,

I would be more than happy to provide free SSL certs at scale for [Online.net](http://Online.net) shared hosting customers.  
How can we work toward that goal ?

---

<div class="post-metadata">

**Author:** ![zagadaa](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zagadaa/32/648_2.png) [@zagadaa](https://community.letsencrypt.org/u/zagadaa)\
**Post date:** [October 20, 2015, 3:24pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/12 "2015-10-20T15:24:28Z")

</div>

Please include Dreamhost too!!!

---

<div class="post-metadata">

**Author:** ![lew](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lew/32/1007_2.png) [@lew](https://community.letsencrypt.org/u/lew)\
**Post date:** [October 20, 2015, 5:49pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/13 "2015-10-20T17:49:56Z")

</div>

I’m wondering if this will work when the website is on a shared hosting provider with multiple domains pointing to the same IP address? Or will I need a private IP address? Either way, if it can work, I’ll start bugging them, trying to get them to contact you.

I don’t have access to the server environment nor any root access. So I couldn’t run the client script. I have access to the web site (of course), so I can put files there, but that’s about it.

Is there a page that describes the pre-requisites for this to work for a given web site.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [October 20, 2015, 8:24pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/14 "2015-10-20T20:24:46Z")

</div>

Hi @lew, you don’t need an individual IP address because of Subject Alternative Names (SAN), which let a single certificate be valid for many different domains, and likely also because of Server Name Indication (SNI), which lets a client indicate which domain name it’s trying to connect to when beginning the TLS session. Each of these has some limitations: there’s a maximum number of SAN names per certificate, SANs reveal in an obvious way exactly which sites may be hosted on the same server, and SNI isn’t supported by some old client software.

If you don’t have access to the server environment, the hosting provider would need to complete the domain validation process on your behalf. We are trying to make it practical for all hosting providers to make use of our services, so the answer for whether we can work with a given provider should in principle almost always be yes, but they may need to do some engineering work to integrate with us.

---

<div class="post-metadata">

**Author:** ![jcjones](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jcjones/32/78_2.png) [@jcjones](https://community.letsencrypt.org/u/jcjones)\
**Post date:** [October 20, 2015, 8:41pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/15 "2015-10-20T20:41:36Z")

</div>

Saw this fly by on Twitter from DreamHost:

> <https://twitter.com/DreamHostCare/status/656558913056342017>

---

<div class="post-metadata">

**Author:** ![thomasc](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/thomasc/32/1018_2.png) [@thomasc](https://community.letsencrypt.org/u/thomasc)\
**Post date:** [October 20, 2015, 10:15pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/16 "2015-10-20T22:15:28Z")

</div>

Hello,

We, at [PulseHeberg.com](http://PulseHeberg.com), are also interested to bring free Let's Encrypt SSL certificates available to our shared hosting's customers.  
I'm also interested to discuss with a LE staff member about any integration of Let's Encrypt.

> [@schoen](#):
>
> Hi @lew, you don't need an individual IP address because of Subject Alternative Names (SAN), which let a single certificate be valid for many different domains, and likely also because of Server Name Indication (SNI), which lets a client indicate which domain name it's trying to connect to when beginning the TLS session. Each of these has some limitations: there's a maximum number of SAN names per certificate, SANs reveal in an obvious way exactly which sites may be hosted on the same server, and SNI isn't supported by some old client software.

If I correctly understood your point, you're saying that a single certificate can be used by multiple domains on a single host. But what about different domains, each one having a different LE SSL certificate on a single host (with a single IP address). It is possible with Let's Encrypt or it requires a private IP address for each domain?

Best regards,  
Thomas Cardonne.

---

<div class="post-metadata">

**Author:** ![riking](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/riking/32/92126_2.png) [@riking](https://community.letsencrypt.org/u/riking)\
**Post date:** [October 20, 2015, 10:58pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/17 "2015-10-20T22:58:32Z")

</div>

> [@thomasc](#):
>
> But what about different domains, each one having a different LE SSL certificate on a single host (with a single IP address). It is possible with Let's Encrypt or it requires a private IP address for each domain?

That sounds like it should be easier, not harder, to do 😛

Though to save on the storage space, you may want to consider using multi-domain certificates for your lower-paying customers.

---

<div class="post-metadata">

**Author:** ![lew](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lew/32/1007_2.png) [@lew](https://community.letsencrypt.org/u/lew)\
**Post date:** [October 22, 2015, 8:01pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/18 "2015-10-22T20:01:23Z")

</div>

Thanks for the explanations. I did some reading. It seems to me that SANs are not relevant in my context as the list of hosts on the IP address is constantly changing (as sites get added and removed). And it feels strange to have one certificate for a bunch of unrelated sites.

But SNI seems to be what I am looking for. I’ll see what my current web hosting provider has to say… The provider’s web server needs to support SNI and they need to have something in place to install your certificates.

---

<div class="post-metadata">

**Author:** ![arek](https://avatars.discourse-cdn.com/v4/letter/a/46a35a/32.png) [@arek](https://community.letsencrypt.org/u/arek)\
**Post date:** [November 9, 2015, 6:38pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/19 "2015-11-09T18:38:18Z")

</div>

Also interested in this (as hosting provider). The goal here would be to provide certificates for all customer web pages BUT also for all services like smtp, imap, pop3, ftp and sql subdomains (thread about non-web usage is here [Use on non-web servers?](https://community.letsencrypt.org/t/use-on-non-web-servers/425/)).

Validation via dns would be easiest to implement (but letsencrypt won’t support it initially), so the other solution is to globally DNAT (at edge of our network) all traffic coming from letsencrypt IP addresses to our single server that would provide all required files/data on 80 port. That should be easy to implement and wouldn’t disrupt normal customer usage, wouldn’t require putting any files into customer web files folders etc. Not sure if this will work though… need to read ACME docs first.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [November 15, 2015, 4:46pm UTC](https://community.letsencrypt.org/t/shared-hosting/384/20 "2015-11-15T16:46:26Z")

</div>

@arek, it’s not clear in the long run that Let’s Encrypt validation IP address will be disclosed (or constant over time), because the CA might use probing from randomized or gradually changing locations to decrease the chance that an attacker who controls a portion of the Internet can trick the validation. I think your IP-address-related method could work right now but wouldn’t be guaranteed to work in the future.

[Next page](https://community.letsencrypt.org/t/shared-hosting/384.md?page=2)
