SSL installation service

Send us the certificate. We will install it on your server today.

A certificate sitting in your inbox is protecting nothing. Our engineers install it on your server, chain it correctly, force the redirect and prove it works from outside your network — at a scheduled time, on credentials you revoke afterwards.

  • Same or next working day. Booked to a time you choose, not whenever we get to it.
  • We generate the CSR too. On your server, submitted to the authority, at no extra charge.
  • One flat fee per server. A wildcard covering forty subdomains is still one installation.
  • From $29. 20 server platforms priced below, one flat fee each.

Book it now, or read on first

The card picks your platform and charges the price shown against it. If you would rather see the whole price list before committing, it is a little further down — and if your setup is not on it, ask us for a quote before you pay anything.

What “installed” means here

Not “the file is on the server”. This is the check we run from outside your network before we close the job, and the one you can repeat yourself any time with our free SSL checker.

  • Certificate served, in date, and matching every name it should
  • Intermediate chain complete down to a trusted root
  • Private key on the server genuinely pairs with the certificate
  • http:// lands on https:// with no redirect loop
  • Old certificate no longer served by any host, worker or balancer

Pick your server

The price changes with the platform, because the work does.

  • Lowest price guarantee
  • 24×7 support
Server Type
$49 $29
You save $20
Add to your order
  • Help from real engineers, 24×7 — before you order as well as after.
Encrypted checkout on sslretail.com

It is not the installing that catches people out

Copying a certificate onto a server is twenty minutes. What takes the afternoon is everything that is still wrong afterwards — and most of it does not show up in the browser you happen to be testing in.

The chain is incomplete

The single most common fault we are called in for. The server sends your certificate but not the intermediate above it. Desktop Chrome fills the gap from cache and looks fine, so you close the ticket — then Android, older Java clients and payment gateways reject the site outright. The diagram below is this failure exactly.

The private key does not match

Generate the CSR twice, or generate it on the wrong machine, and you have a certificate that will never pair with the key you kept. Nothing tells you until the service refuses to start, usually at the point you have already scheduled the change.

The old certificate is still being served

Load balancers, CDNs, control panels and Apache virtual hosts all cache or duplicate certificate state. It is genuinely common to install correctly and still be serving the expired one to half the internet.

HTTPS works, but the site still says Not secure

One hard-coded http:// image or script and the padlock does not appear. Fixing mixed content means finding it, which means looking rather than guessing.

Nothing forces visitors onto it

Without a redirect, the certificate is installed and almost nobody uses it. Get the redirect wrong instead and you build a loop that takes the site down.

The fault that looks fine on your machine

A browser trusts your certificate only if it can build an unbroken chain from it up to a root already on the device. Your server has to send the middle link. Leave it out and desktop Chrome often papers over the gap from its own cache — so you see a padlock, and your customers on phones see a warning.

Why it is worth someone else doing: the broken version above returns a padlock on the machine you are testing on. You cannot find this by looking at your own site — you find it by testing from outside, which is the last thing we do on every job.

What you are actually paying for

It is a one-off fee against a certificate you will run for a year or more. Here is the whole of it, itemised, with the things other people charge extra for marked.

Generating the CSR and key on your server Often billed as a separate job
Submitting it and completing validation with the authority Included
Installing the certificate and the full intermediate chain Included
Forcing HTTP to HTTPS without building a redirect loop Included
Checking the result from outside your network Included
A wildcard across every subdomain it covers Charged as one installation
A multi-domain certificate across every name on one server Charged as one installation
Re-installing free if the authority reissues industry-wide Included for the whole term

One honest exception. The one thing that is not included: a second server. A multi-domain or wildcard certificate on three machines is three installations, because it is three lots of work. We would rather say that here than at the invoice.

Ready to book it? Pick your platform and we will start the same or next working day. If your setup is unusual, ask for a quote instead — it costs nothing.
$29 from, per server

You are not handing over your root password

The access question stops more of these orders than the price does. So: you decide what we get, for how long, and you switch it off yourself when the job is done.

A temporary account, made by you

Create a login for the job with the access the work needs and nothing else. Most control panel installs need far less than full administrative rights.

Or nobody gets a login at all

If you have the machine in front of you, put us on a screen-sharing session instead and watch every command. Nothing is typed that you have not seen.

You revoke it when it is finished

Delete the account or change the password the moment we confirm. We keep no credentials after the job is closed.

At a time you picked

Restarting a web service drops connections. We book it for the quiet hour you nominate rather than the middle of your trading day.

Your server access stays confidential, end to end

You are letting someone into the machine your business runs on. That deserves specific commitments rather than the word “secure”, so here are ours — each one is something you can hold us to.

Access is temporary by design

We ask for a purpose-made account rather than your existing one, scoped to the job. Your real administrator password never has to leave your hands, and most control panel installs need far less than full rights.

Submitted on an encrypted form, not by email

Server details go through the secure form on your own order page, served over TLS on a SHA-256 signed certificate, and are held encrypted rather than as readable text. Email is the wrong place for a server password and we do not ask you to use it. If you would rather transmit nothing at all, take the screen-share route instead.

Not shown to the engineer as readable text

The details you submit are not exposed in the clear to the person doing the installation. They are used to complete the job and for nothing else.

Used only for the work you paid for

The access is used for the installation and nothing else. We do not browse your files, read your databases, or look at anything the certificate does not require.

One named engineer, not a pool

Your job is handled by the engineer assigned to it. Access is not circulated around a team or handed to a subcontractor.

Destroyed once the installation is finished

The details you submitted are destroyed when the job completes. That is also the point at which we tell you to revoke the account from your side, so the access is closed twice over — on purpose.

Your certificate and key are yours alone

The private key we generate lives on your server. We keep no copy of it, and we never share your certificate, key, domains or server details with anyone outside the job.

Do not take our word for either of these. Two of these you can verify yourself rather than take on trust: revoke the access when we tell you the job is done, and run our free SSL checker against your own site to confirm the result independently of anything we say.

What happens to the login you send us

Four stages, and a password in an inbox is not one of them. The details go straight from your browser into the encrypted form on your order page, and stop existing when the job does.

Find your setup, see the price

Every price below is the live price in the cart. If your platform is not here it does not mean we cannot do it — it means we want to look at it before you pay.

Control panels

The cheapest to install, because the panel does half the work. If you are on shared or reseller hosting this is almost certainly you.

cPanel $29$49
WHM $29$49
Godaddy Server $29$49
Media Temple (GRID) $49$89
Plesk $49$89

Web and application servers

A configuration file and a service restart. The chain and the redirect are where these go wrong, which is most of what you are paying us to get right.

Apache + Mod SSL + OpenSSL $49$89
Apple Mac OS $49$89
Jetty Java HTTP Servlet $49$89
LiteSpeed $49$89
Microsoft IIS $49$89
Nginx Server $79$89
Tomcat server $79$89

Mail and communications

Several hostnames answering as one system. Miss one and every desktop in the building prompts on Monday morning.

Citrix Secure Gateway $49$89
Microsoft Exchange $49$89
MS Office Communications Server (OCS) $49$89

Cloud, appliances and everything else

Load balancers, orchestration, cameras, directory servers. Priced higher because they genuinely take longer, and quoted individually when they are unusual.

Amazon Web Services $49$89
F5 Big IP Controller $49$89
Kubernetes (GKE) $99
Novell eDirectory server $120
CCTV Camera ONVIF $79$89

Not on the list? That is not a no. Send us what you are running and we will price it, or tell you plainly if it is not something we should be touching. Ask for a quote — there is no charge and no obligation.

The whole process, start to finish

Six stages, none of which happen without you knowing. Nothing touches your server until you have agreed a window and created the access yourself — and the access stops existing at stage six.

1

You order and pick your platform

The price you pay is the one shown against your server type. If your setup is unusual, ask for a quote first and pay nothing until you have it in writing.

You
Choose your server type and pay
Us
Nothing yet — we have no access at this point
2

We come back to you, same or next working day

A real engineer reads the order, tells you what the job needs, and asks for a window that suits you. If anything about the certificate looks wrong for what you are trying to cover, this is where we say so.

You
Tell us your quiet hour
Us
Confirm scope, flag anything wrong before we start
3

You submit access through the secure form

Your order page carries an encrypted form for the login URL, the temporary username and password, and the domain. It is served over TLS, the details are stored encrypted rather than in plain text, and they are not shown to the engineer doing the work. Nothing goes by email — there is no need to put a password in an inbox.

You
Create temporary access, submit it on the form
Us
Hold it encrypted, use it only in your window
4

The engineer does the work

CSR generated on the server if you have not got one, validation completed with the authority, certificate installed, full chain attached, redirect set. One named engineer does your job start to finish.

You
Watch over the screen share, or leave us to it
Us
Install, chain, redirect — nothing outside the job
5

We prove it from outside your network

Chain complete to a trusted root, dates and names right, http:// landing on https:// with no loop, no stale certificate still being served. You get the result, not a claim.

You
Check it yourself with our free SSL checker
Us
Send you the external verification
6

You revoke, and we hold nothing

Delete the temporary account or change the password. Our copy of anything you sent is destroyed when the ticket closes, and the job is finished with you holding every key again.

You
Delete the access you created
Us
Destroy credentials, keep no copy

What people said after we had done it

4.73 out of 5, from 15 ratings left by buyers of this service. They are published unedited on the reviews page and we do not choose which ones appear.

Worth every cent for the time it saved us. No downtime at all during the install.

Mikkel Nilsson · Verified buyer

The engineer knew our server type better than we did. They documented what they changed, so our own notes stayed accurate. Would buy here again without hesitating.

Katrin Richter · Verified buyer

Sent them the certificate files in the morning and it was live before lunch. They tested the chain afterwards and sent proof it was correct. Already ordered a second one for another project.

Kavya Gupta · Verified buyer

Read every review of this service →

Questions people ask before they order

Could I not just do this myself?

On cPanel or Plesk with a single domain certificate, very possibly — it is a paste box and a button, we publish the guides for it, and support on that is free with any certificate you buy from us. Pay for this when the platform has no panel, when several hostnames or servers are involved, when the site earns money and cannot be down, or when you have already tried and something is still wrong.

Do you need my root password?

No. Create a temporary account with only the access the job needs, and delete it when we confirm the work is done. If you would rather issue no credentials at all, we will do the whole thing over a screen-sharing session while you watch. We do not keep credentials after a job closes.

Will my site go down?

Applying a certificate needs the web service reloaded, which drops connections in progress. That is why we agree a window with you first and work inside it. On a control panel it is normally seconds, and several of the reviews below are from people who saw no interruption at all.

Do you generate the CSR, or do I?

We do, on your server, and we submit it to the certificate authority for you. There is no extra charge for it. Generating the request on the machine that will serve the certificate is also what stops the commonest failure of all — a certificate that never matches the key you kept.

I have a wildcard. Do I pay per subdomain?

No. A wildcard is one certificate and one installation whatever it covers, whether that is three subdomains or forty. The same goes for a multi-domain certificate carrying every name you own, as long as they are on one server.

I need it on more than one server.

Each server is a separate installation and is charged as one, because each is a separate piece of work with its own chain and its own restart. Tell us how many and we will quote the set in one go rather than making you order them one at a time.

What if I bought the wrong certificate?

Tell us before we start. Working out that a single-domain certificate will never cover the subdomain you needed is a normal part of this job, and we would rather find it at the beginning. Where a swap is possible under the issuing authority’s rules we will help you arrange it.

What happens when it expires, or gets reissued?

A renewal a year later is a new installation and is charged again. A reissue forced on everybody by the industry — the sort of thing that happened with the move off SHA-1 — is not your fault, so we regenerate and reinstall for nothing for the rest of your term.

How quickly does it start?

We come back to you the same or the next working day once payment clears, and the work itself is booked to a window that suits you. Where the certificate is already issued and the server is a control panel, people below describe it finishing inside a couple of hours.

My platform is not in your list.

Ask before you pay. The list is the platforms we have priced because we see them often; it is not the limit of what we will touch. Send us what you are running and we will either quote it or tell you honestly that it is not something we should be doing.

Do I have to have bought the certificate from you?

No. The order form has an option for a certificate bought somewhere else, and one for a certificate you have already generated yourself. What matters is that the certificate, the request it was issued against and the private key all belong to each other — and if you are not sure they do, our free key matching tool will tell you before you pay for anything.

How do I send you the server login?

Through the encrypted form on your order page, once the order is placed. It is served over TLS on a SHA-256 signed certificate, the details are stored encrypted rather than as readable text, they are not exposed in the clear to the engineer, and they are destroyed when the installation is finished. We never ask for a server password by email.

How do I know it worked?

You get the result of a check run from outside your own network: the chain complete down to a root your visitors trust, the dates and the names right, and http:// landing on https:// without a loop. Our free SSL checker runs the same test whenever you want to repeat it.

That is everything we would want to know before paying 20 platforms priced, one flat fee per server, and the access closed off at both ends when the job is done.
$29 from, per server

Not sure it is worth it? Ask first.

Tell us the platform, how many servers, and what the certificate covers. We will tell you what it costs — and if it is a ten-minute job you should do yourself, we will tell you that instead. There is no charge for asking and no obligation after.

Ask for a free quote