What does "AutoSSL reduced SSL coverage" mean?

If you have received an email where "AutoSSL reduced SSL coverage" appears in the subject field, it is because cPanel has had problems setting up SSL for one or more domains/subdomains.

The message will contain a list of all domains that failed DCV (Domain Control Validation). The DCV is created to verify that you have access to the domain name for which an SSL certificate is being issued. Next to each domain name that failed DCV, it will also state why the validation failed. AutoSSL tries to do DCV either via DNS (if the domain uses our name servers) or via HTTP, where a temporary file is created in the {$dokumentrod}/.well-known/pki-validation/ folder.

Validation can fail for several reasons, but the most typical are:

  • the domain name does not point to the ip address of your web hosting solution
  • no A record exists for the domain name
  • it is not possible to validate via HTTP because something is blocking access to the generated file

How to solve it?

The solution to the problem depends on why the DCV has failed. If the DCV has failed because the A record of the domain name does not point to the IP address of your web hosting solution, it will be necessary for the A record to either be corrected to point to the IP address of your web hosting solution or for the domain name to be excluded from AutoSSL.
If the DCV has failed because the domain name has no A record, you can set up an A record at your DNS provider that points to the IP address of your web hosting solution. If you do not need the specific domain name, it can simply be excluded from AutoSSL.
If you do not use our name servers, AutoSSL will try to validate via HTTP. In some cases, security software (eg. WordFence for WordPress) may deny access to the pki-validation folder on the web hosting solution. If you have a rule in the .htaccess file on your website that denies access to this folder this will need to be disabled.

 

How to exclude a domain name from AutoSSL?

In some cases, you may not need the system to issue an SSL certificate for the domain name. This happens e.g. applicable if you use another provider for the website or a proxy such as CloudFlare for some of your domains or subdomains.
In these cases, you should instead exclude the specific domains from AutoSSL.

  1. Log in to your cPanel account via https://your-domain.dk/cpanel (replace your-domain.dk with your own domain name)
  2. Go to Security > SSL/TLS Status
    SSL/TLS Status ikon
  3. Tryk på "Exclude from AutoSSL" ved det domæne, som AutoSSL ikke skal udstede SSL-certifikat til
    Ekskluder fra AutoSSL

 

AutoSSL will no longer include the domain name in the certificate being issued.

Note: Some domains/subdomains must be included in AutoSSL if you want to use the functionality that the domain/subdomain offers. If you use our e-mail server, you must e.g. do not exclude "mail.domain.dk" from AutoSSL, as this will result in a certificate error in your email program.

 

 

  • 1 Users Found This Useful
Was this answer helpful?

Related Articles

How do I enable HSTS?

HSTS (HTTP Strict-Transport-Security) is a security policy where the web server tells your...

Force SSL (HTTPS) on your domain names

SSL (HTTPS) is not forced on your domain names by default when an SSL certificate has been set up...

Set up SSL for free

We offer free SSL certificates for our costumers on their domains so the users of their website...