In cPanel, go to SSL/TLS → Manage SSL Sites. You'll need three things from your certificate authority: the certificate (CRT), your private key, and the CA bundle (intermediate certificates).
- Paste the certificate into the "Certificate" field — cPanel will attempt to auto-fill the domain and private key if it recognizes them.
- Paste the private key into the "Private Key" field.
- Paste the CA bundle into the "Certificate Authority Bundle" field — skipping this causes "not trusted" warnings on some devices even though the cert itself is valid.
- Click Install Certificate.
Or skip all of it: AutoSSL
If you don't specifically need a paid certificate (EV, extended warranty, wildcard from a specific vendor), cPanel's AutoSSL issues and auto-renews free domain-validated certificates for every domain on the account with zero manual steps. For most sites, this is the better default.