Trustico® CaaS cPanel Plugin

The Trustico® CaaS cPanel plugin brings automated SSL Certificate management directly into the cPanel control panel. Website owners can retrieve, install, and automatically reissue commercial SSL Certificates without leaving the cPanel dashboard - no command line, no SSL Certificate Signing Request (CSR) generation, no manual file uploads, and no expiry anxiety. Learn About Certificate as a Service (CaaS) 🔗

Ready to Install? Hosting providers can download and install the Trustico® CaaS cPanel plugin on their servers. View Our CaaS cPanel Plugin Installation Guide 🔗

What the Plugin Does

The Trustico® CaaS cPanel plugin automates the entire SSL Certificate lifecycle. It retrieves a signed SSL Certificate from the Certificate Authority (CA), installs the SSL Certificate along with the Private Key and Certificate Authority (CA) bundle into cPanel, and configures automatic reissue so the SSL Certificate is reissued before it ever expires. All of this happens through a simple form inside the cPanel dashboard.

The plugin supports both Trustico® branded and Sectigo branded SSL Certificates, including Domain Validation (DV) and Organization Validation (OV) products. Single site and Wildcard SSL Certificates are both supported, with the plugin handling the appropriate validation method automatically. Explore Traditional SSL Certificates vs Certificate as a Service (CaaS) 🔗

How It Works

The plugin uses the Automatic Certificate Management Environment (ACME) protocol with External Account Binding (EAB) to connect your Trustico® SSL Certificate order to your cPanel hosting environment. When you purchase a CaaS-enabled SSL Certificate from Trustico® you receive two credentials : an EAB Key ID and an EAB HMAC Key. These are the only values you need to enter into the plugin.

CaaS cPanel Plugin Guide Get Your EAB Credentials

Open the plugin from the "Security" section in your cPanel dashboard, select your virtual host, choose which domain names to include on your SSL Certificate, enter your EAB credentials, and click "Retrieve SSL Certificate." The plugin handles domain validation, SSL Certificate retrieval, installation into cPanel, and automatic reissue configuration. You can close the page during processing and return later to check the result. View Our CaaS cPanel Plugin Guide 🔗

What Happens Behind the Scenes

The plugin verifies that your domain's document root is accessible, registers with the Automatic Certificate Management Environment (ACME) server using your EAB credentials, performs domain validation (HTTP-01 for standard domains or DNS-01 for Wildcard SSL Certificates), retrieves the signed SSL Certificate, and installs it into cPanel's SSL management system. Your domain immediately begins serving HTTPS.

Once the SSL Certificate is installed, the plugin configures automatic reissue. When the SSL Certificate approaches its expiry window, it is automatically reissued and reinstalled without any action required on your part. This is particularly important as the industry moves towards shorter SSL Certificate validity periods, with maximum validity decreasing to 200 days from March 2026 and eventually to just 47 days.

SSL Certificate Coverage

The plugin displays your SSL Certificate coverage organized into three sections : the Virtual Host table showing the currently installed SSL Certificate, the Website Domains table showing the domain names your visitors use to access your website, and the Service Domains table showing cPanel service subdomains such as webmail and webdisk. Each domain name is checked against the installed SSL Certificate's Subject Alternative Names (SANs) using the same method cPanel uses on its own SSL/TLS Status page.

Color-coded status labels make it easy to see which domain names are secured at a glance. Domains covered by the installed SSL Certificate show "Active" in green, while domains not covered show "Inactive" in gray. Additional labels indicate when an SSL Certificate is approaching expiry or has already expired. For a detailed explanation of each coverage section and status label, refer to our comprehensive guide. View Our CaaS cPanel Plugin Guide 🔗

Wildcard SSL Certificate Support

Wildcard SSL Certificates allow you to secure all subdomains under a single domain - such as www.example.com, mail.example.com, and shop.example.com - with a single SSL Certificate. It is important to understand that a Wildcard SSL Certificate covers subdomains only. The wildcard pattern *.example.com does not cover the base domain (example.com) itself. To secure the base domain alongside the wildcard, it needs to be included as a separate Subject Alternative Name (SAN) on the same SSL Certificate.

Trustico® generally bundles both together when you purchase a Wildcard SSL Certificate, so your licensed domain names will typically authorize issuance for both *.example.com and example.com. This means you get a single SSL Certificate that protects your base domain and every subdomain.

The plugin fully supports Wildcard SSL Certificates and handles DNS-01 validation automatically. When you select a Wildcard domain name, the validation method switches to DNS-01 and the plugin manages the required Domain Name System (DNS) TXT records through cPanel's Domain Name System (DNS) management. Learn About Wildcard SSL Certificates 🔗

Important : Wildcard SSL Certificate support using DNS-01 validation requires that the Domain Name System (DNS) zone for your domain is managed by the same cPanel server. If your domain uses external Domain Name System (DNS) providers such as Cloudflare or Amazon Route 53, the plugin will detect this and display an error message.

Security Built Into Every Step

The plugin has been designed with security as a priority throughout. EAB credentials are passed via environment variables rather than command-line arguments and are cleared from memory after use. All operations are protected by Cross-Site Request Forgery (CSRF) validation using cPanel session tokens. A five-minute cooldown between operations per domain prevents overuse of Certificate Authority (CA) rate limits.

Logs displayed through the "Show Details" view are sanitized to remove server paths, IP addresses, and credential values. Server-side error logs use Coordinated Universal Time (UTC) timestamps, automatic rotation at one megabyte, and file permissions restricted to the account owner only. The plugin runs entirely with cPanel user permissions - no root access is required or used.

For Hosting Providers

The Trustico® CaaS cPanel plugin is designed for easy deployment across your cPanel server infrastructure. A single installation makes the plugin available to every cPanel user on the server, appearing under the "Security" section in their dashboard. The plugin requires a cPanel server running the Jupiter theme with PHP 7.4 or later and Secure Shell (SSH) root access for the initial installation only.

For detailed installation instructions, server requirements, uninstallation procedures, and feature management options, refer to our installation guide. View Our CaaS cPanel Plugin Installation Guide 🔗

Tip : Hosting companies interested in offering Trustico® SSL Certificates to their customers through the cPanel plugin can explore our partner service for volume pricing and integration support. Explore The Trustico® Partner Service 🔗

Obtaining Your EAB Credentials

To use the Trustico® CaaS cPanel plugin, you need an active Trustico® SSL Certificate order that supports Certificate as a Service (CaaS). When you purchase a qualifying SSL Certificate, your order includes the EAB Key ID and EAB HMAC Key credentials required by the plugin.

You can find your credentials in your order confirmation e-mail. If you have not yet purchased an SSL Certificate, you can browse the available CaaS-enabled products on the Trustico® website. Discover How to Obtain Your CaaS Credentials 🔗

Ready to Install? Hosting providers can download and install the Trustico® CaaS cPanel plugin on their servers. View Our CaaS cPanel Plugin Installation Guide 🔗

Getting Started

If you are a website owner, ask your hosting provider whether the Trustico® CaaS cPanel plugin is installed on their server. If it is, simply navigate to "Security" in your cPanel dashboard and click "Trustico® SSL Certificates" to open the plugin. For a detailed step-by-step walkthrough covering every feature, troubleshooting guidance, and frequently asked questions, refer to our comprehensive guide. View Our CaaS cPanel Plugin Guide 🔗

CaaS cPanel Plugin Guide CaaS cPanel Plugin Installation Get Your EAB Credentials

If your hosting provider has not yet installed the plugin, you can direct them to the installation guide. If you manage your own cPanel server, the installation requires only a single script run as root via Secure Shell (SSH). Learn About Certificate as a Service (CaaS) 🔗

Most Popular Questions

Learn about the Trustico® CaaS cPanel plugin, which automates the entire SSL Certificate lifecycle within the cPanel dashboard. This page covers step-by-step usage for website owners, the three-section SSL Certificate coverage display (Virtual Host, Website Domains, and Service Domains), Wildcard SSL Certificate support with automatic DNS-01 validation switching, security features, and installation instructions for hosting providers.

What Does the Trustico® CaaS cPanel Plugin Provide?

The plugin automates the entire SSL Certificate lifecycle within the cPanel dashboard. It retrieves a signed SSL Certificate from the Certificate Authority (CA), installs it along with the Private Key and Certificate Authority (CA) bundle into cPanel, and configures automatic reissue so the SSL Certificate is reissued before it expires.

How Can SSL Certificates Be Retrieved Using the Plugin?

Navigate to the "Security" section in your cPanel dashboard, click Trustico® SSL Certificates, select your virtual host from the dropdown, check the domain names you want to include in the Website Domains table, select your SSL Certificate type, enter your EAB Key ID and EAB HMAC Key, and click Retrieve SSL Certificate. The plugin handles domain validation, retrieval, installation, and automatic reissue configuration.

What Is a Virtual Host?

A virtual host is the primary hosted domain on your cPanel account. When you select a virtual host from the dropdown, three sections appear showing the current SSL Certificate coverage : the Virtual Host table, the Website Domains table, and the Service Domains table.

What Are Website Domains and Service Domains?

Website Domains are the domain names your visitors use to access your website, such as the root domain, the www version, and the mail subdomain. Service Domains are cPanel service subdomains such as cpanel, webmail, and webdisk. Service Domains are automatically secured when your SSL Certificate includes them through a Wildcard SAN or an explicit domain name.

Where Do I Find My EAB Credentials?

Your EAB Key ID and EAB HMAC Key are included with your Trustico® SSL Certificate order. You can find them in your order confirmation e-mail. These are the only credentials you need to use the plugin.

What Do the SSL Certificate Status Labels Mean?

Six color-coded labels indicate the coverage status. Active (green) means the domain is covered by the installed SSL Certificate's SANs with more than 30 days remaining. Renew Soon (amber) means seven to 29 days remaining. Expiring (red) means within seven days of expiry. Expired (red) means the SSL Certificate has expired. Inactive (gray) means the domain is not covered by the installed SSL Certificate's SANs. No SSL (amber) means no SSL Certificate is installed on the virtual host.

How Does the Plugin Determine SSL Certificate Coverage?

The plugin checks each domain name against the installed SSL Certificate's Subject Alternative Names (SANs) using the same method cPanel uses on its own SSL/TLS Status page. A domain showing Active means the SSL Certificate's SANs include that domain name. A domain showing Inactive means the SSL Certificate does not cover it.

What Are the Server Requirements for the Plugin?

The plugin requires a cPanel server running the Jupiter theme with PHP 7.4 or later, which is standard on all supported cPanel platforms such as AlmaLinux 8 and later. Secure Shell (SSH) root access is required for installation only. No additional PHP extensions or server modifications are needed.

How Does a Hosting Provider Install the Plugin?

Installation is a one-time operation performed via Secure Shell (SSH) as root. The installation script downloads and verifies the Automatic Certificate Management Environment (ACME) client using SHA-256 checksum verification, copies the plugin files into the cPanel theme directory, registers the plugin with cPanel's Feature Manager, and rebuilds the icon sprites.

Does the Plugin Support Wildcard SSL Certificates?

Yes. The plugin fully supports Wildcard SSL Certificates using DNS-01 validation. When a Wildcard domain name is checked in the Website Domains table, the Validation Method automatically switches to DNS-01 and the dropdown is locked. The Domain Name System (DNS) zone for the domain must be managed by the same cPanel server.

How Does the Plugin Handle Security?

EAB credentials are passed via environment variables and cleared from memory after use. All operations are protected by Cross-Site Request Forgery (CSRF) validation using cPanel session tokens. A five-minute cooldown prevents overuse of Certificate Authority (CA) rate limits. Logs are sanitized to remove sensitive information, and the plugin runs entirely with cPanel user permissions.

Can I Uninstall the Plugin Without Losing My SSL Certificates?

Yes. The uninstall script removes the plugin files and deregisters from the Feature Manager, but per-user data including installed SSL Certificates and reissue configurations is preserved separately. A cleanup utility is included for removing per-user data on an individual basis if needed.

Sectigo® CaaS DV Single Site vs Wildcard Comparison

Certificate as a Service (CaaS) provides automated SSL certificate management through APIs. Choose Single Site for individual domain automation, or Wildcard for comprehensive subdomain coverage with full API-driven certificate lifecycle management.

Feature Sectigo® CaaS DV Single Site Sectigo® CaaS DV + Wildcard
Service Type Certificate as a Service (CaaS) Certificate as a Service (CaaS)
Coverage Single Domain Only Unlimited Sub Domains
Domains Covered www.example.com + example.com *.example.com + example.com
Automation Level Fully Automated Fully Automated
API Access Full RESTful API Full RESTful API
Validation Level Domain Validation (DV) Domain Validation (DV)
Validation Methods E-Mail / DNS / HTTP / HTTPS E-Mail / DNS / HTTP / HTTPS
Issuance Time Very Fast! Issued Within Minutes Very Fast! Issued Within Minutes
Auto-Renewal Automated Renewal Available Automated Renewal Available
Certificate Management Centralized Dashboard Centralized Dashboard
Integration Options API, Webhooks, SDK API, Webhooks, SDK
Ideal For SaaS Platforms, Single Domain Apps Multi-tenant SaaS, Complex Infrastructures
Scalability Per-Domain Scaling Automatic Subdomain Coverage
Warranty $500,000 USD $500,000 USD
Encryption Strength 256-bit SSL Encryption 256-bit SSL Encryption
Browser Compatibility 99.9% Browser Trust 99.9% Browser Trust
Dual Domain Coverage Includes Root Domain SAN Free! Includes Root Domain SAN Free!
Reissuance Unlimited Unlimited
Deployment Options Cloud, On-Premise, Hybrid Cloud, On-Premise, Hybrid
Information Page Product Information Page 🔗 Product Information Page 🔗
Your Trustico® Price $ 1,255.00 MXN $ 5,018.00 MXN
Purchase Options Instant - Buy Now 🔗 Instant - Buy Now 🔗