X
Published: 2025-04-24 | Updated: 2026-08-26

How to Choose an SSL Certificate


Quick Answer

Choose or manage the certificate based on the hostnames you need to protect, the validation level, the server platform and whether you control DNS. Keep the private key secure, complete validation, install the full certificate chain and verify the live HTTPS connection before relying on the certificate.


Before You Begin

  • Identify every hostname the certificate must cover.
  • Confirm that you control DNS or the required validation channel.
  • Generate and securely retain the private key when a CSR is required.


NiceNIC Instructions

How to install SSL certificates SSL certificate installation is typically performed by the hosting company that provides services for the domain. However, you may also choose install an SSL certificate yourself. Select your server type from the list below to find detailed instructions for installation. The SSL on your domain name was activated, please find and add the DNS records to complete the verification before you can download the certificate files through your control panel: My Account > My Products > SSL Certificates > Detail >….

After you complete the DNS-record validation, you can download the certificate files by the same approach. Installing SSL Certificate Notes If you host your domain name with NiceNIC, simply provide us with your certificate and we'll be happy to install it for you. Please note that on all NiceNIC, Shared Hosting servers, a special NiceNIC, SSL plugin installs a 1-year free PositiveSSL certificate automatically on the newly added subdomain or add-on. It works the same way for the main domain in the newly purchased hosting account.

The plugin can also be used for manual installation (in a few clicks) of PositiveSSL and EssentialSSL certificates. A dedicated IP address is required to install an SSL certificate. However, you may install your SSL certificate on a shared IP address using the Server Name Indication (SNI) protocol extension available in your cPanel. You can learn more about the differences between a dedicated IP and SNI technology in this article.


How to Verify

Open the HTTPS site from a clean browser session and inspect the certificate subject, SAN hostnames, issuer, validity dates and chain. Test every hostname covered by the certificate and confirm that HTTP redirects behave as intended.


Troubleshooting

  • DNS validation records are missing, incorrect or added at the wrong DNS provider.
  • The certificate does not include the hostname being opened.
  • The private key does not match the certificate or CSR.
  • The server is missing an intermediate certificate or is still presenting the old certificate.


Frequently Asked Questions

Can I reuse the same certificate after moving servers?

Often the certificate can be reinstalled if you still have the matching private key and the certificate remains valid. Reissue it when the key, CSR or certificate details must change.

Why does the browser still show the old certificate?

The server or load balancer may still present the old certificate, another virtual host may be selected, or an intermediate cache may not have reloaded the configuration.

When should I submit a ticket?

Submit a ticket when validation remains pending after the published records are visible, or when the NiceNIC order does not provide the expected certificate files.


Related NiceNIC Guides


If the issue continues after you complete the checks above, submit a NiceNIC support ticket with the affected domain or product, the exact error message, the time of the issue and the troubleshooting already completed.

Need help? We're always here for you. Human Support
Copyright © 2006–2026 NICENIC INTERNATIONAL GROUP CO., LIMITED. All Rights Reserved. · U.S. Affiliate: NICENIC LLC