Web Hosting Knowledge Base Web Hosting Knowledge Base
  • Home
Get Started
Web Hosting Knowledge Base Web Hosting Knowledge Base
Get Started
Web Hosting Knowledge Base Web Hosting Knowledge Base
  • Home
loading
  1. Home
  2. Add on Services
  3. How to troubleshoot SSL certificate renewals for Cloudflare-enabled domains
Updated on June 21, 2024

Add on Services

  • Folder icon closed Folder open iconHow to back up your data using Dropmysite
  • Folder icon closed Folder open iconHow to monitor blacklisted sites using Dropmysite
  • Folder icon closed Folder open iconHow to maximize Dropmysite backup storage space
  • Folder icon closed Folder open iconHow to restore your data using Dropmysite
  • Folder icon closed Folder open iconWhat is the Cloudflare CDN?
  • Folder icon closed Folder open iconHow to activate Cloudflare
  • Folder icon closed Folder open iconUsing SSL with Cloudflare
  • Folder icon closed Folder open iconTroubleshooting Cloudflare connections
  • Folder icon closed Folder open iconHow to use Cloudflare to defend against DDoS attacks
  • Folder icon closed Folder open iconSetting up Let's Encrypt and Cloudflare Universal SSL for end-to-end encryption
  • Folder icon closed Folder open iconHow to turn off Cloudflare temporarily for maintenance or development
  • Folder icon closed Folder open iconSetting up cPanel SSL and Cloudflare Universal SSL for end-to-end encryption
  • Folder icon closed Folder open iconHow to troubleshoot SSL certificate renewals for Cloudflare-enabled domains
  • Folder icon closed Folder open iconHow to clear the Cloudflare cache
  • Folder icon closed Folder open iconDiscontinuation of Cloudflare CDN cPanel and Plesk plugins
  • Folder icon closed Folder open iconHow to configure DNS records for email in Cloudflare
  • Folder icon closed Folder open iconRefer-a-friend program
  • Folder icon closed Folder open iconAffiliate program information
  • Folder icon closed Folder open iconHow to use the QUIC.cloud CDN with WordPress
  • Folder icon closed Folder open iconUsing Cloudflare
  • Folder icon closed Folder open iconSecure Sockets Layer (SSL) certificates information
  • Folder icon closed Folder open iconWHMCS hosting information
  • Folder icon closed Folder open iconHow to become a domain and SSL reseller with eNom
  • Folder icon closed Folder open iconHow to activate an SSL certificate as an eNom reseller
  • Folder icon closed Folder open iconHostvento Hosting promotions
  • Folder icon closed Folder open iconHow to order a cPanel license
  • Folder icon closed Folder open iconHow to configure OpenSRS access for WHMCS
  • Folder icon closed Folder open iconHow to sign up for a MailChimp account
  • Folder icon closed Folder open iconDropmysite cPanel plugin
  • Folder icon closed Folder open iconHow to order a WHMCS license
  • Folder icon closed Folder open iconHow to order a Blesta license
  • Folder icon closed Folder open iconHow to reset the administrator password in WHMCS
  • Folder icon closed Folder open iconHow to remove a banned IP address in WHMCS
  • Folder icon closed Folder open iconQUIC.cloud

How to troubleshoot SSL certificate renewals for Cloudflare-enabled domains

Estimated reading: 3 minutes 184 views

This article provides instructions on how to troubleshoot problems that may occur when you try to renew an SSL certificate on a Cloudflare-enabled domain.Table of Contents

  • Problem
  • Resolution

Problem

When you try to renew an SSL certificate on a Cloudflare-enabled domain, the renewal fails. Specifically, when you go to the SSL/TLS page in the SECURITY section of the cPanel home screen, you see the following message:

DNS DCV: No local authority: “example.com”; HTTP DCV: “cPanel (powered by Sectigo)” forbids DCV HTTP redirections.

Similarly, if you have a Reseller hosting account, when you go to the Manage AutoSSL page of the SSL/TLS section of WebHost Manager (WHM), you see the following message:

WARN Local HTTP DCV error (example.com): “cPanel (powered by Sectigo)” forbids DCV HTTP redirections.

Resolution

To resolve this problem, you must disable forced HTTPS connections in the Cloudflare settings for the domain. If SSL renewals still fail, there are a few other Cloudflare settings you can check.

You do not need to disable Cloudflare entirely for SSL certificate renewals. Cloudflare only needs to be temporarily disabled when an SSL certificate is installed for the first time.

To fix SSL certificate renewals for a Cloudflare-enabled domain, follow these steps:

  1. Log in to the Cloudflare account associated with the domain.
  2. On the Home tab, click the domain:Cloudflare - Home tab - Select domain
  3. Click the SSL/TLS icon, and then click the Edge Certificates tab:
    Cloudflare - SSL/TLS icon - Edge Certificates tab
  4. Click the slider to disable the Always Use HTTPS option:
    Cloudflare - SSL/TLS - Edge Certificates - Always Use HTTPS sliderYou should leave this option disabled permanently. If you want to enforce HTTPS usage on your site, you can use .htaccess redirects as described in this article. Alternatively, if you are using WordPress, you can enforce HTTPS usage as described in this article.
  5. SSL certificate renewals should now complete successfully. However, if they still fail, check the following settings in Cloudflare:
    • Automatic HTTPS Rewrites: This option is located on the Edge Certificates tab of the SSL/TLS section in Cloudflare. If it is enabled, disable it temporarily for SSL renewals.
    • SSL/TLS encryption mode: This option is located on the Overview tab of the SSL/TLS section in Cloudflare. If Full (strict) mode is enabled, set it instead to Full mode temporarily for SSL renewals.

Still stuck? How can we help?

How can we help?

Was this page helpful? Yes No

Share this Doc

How to troubleshoot SSL certificate renewals for Cloudflare-enabled domains

Or copy link

Clipboard Icon
CONTENTS
Leaf Illustration

© 2023 All Rights Reserved by Hostvento