Free certificates issued by AutoSSL (Let's Encrypt / cPanel) renew automatically before they expire — you don't need to do anything. To confirm, log in to cPanel, open SSL/TLS Status, and check the expiry date and green padlock.
- If a domain isn't auto-renewing, select it and click Run AutoSSL.
- Make sure DNS still points to your Toshost server so validation succeeds.
For a paid third-party certificate, renewal is manual: buy the renewal from your provider, generate a fresh CSR if required, then install the new certificate under Manage SSL sites. Paid certificates do not renew themselves, so watch the expiry date. If AutoSSL keeps failing to renew, open a ticket and we'll look into the validation issue.