Plesk's SSL/TLS Certificates section lets you either upload a certificate you already have, or request a free one directly through Plesk's built-in Let's Encrypt integration.
Uploading an existing certificate
Under Websites & Domains → SSL/TLS Certificates → Upload Certificate, paste in your certificate, private key, and CA bundle in the corresponding fields, then assign the certificate to your domain under Hosting Settings.
Using the built-in Let's Encrypt option
The "Install" button next to the Let's Encrypt option in the same section issues and installs a free certificate automatically, including setting up auto-renewal — the simpler path unless you specifically need a paid certificate's validation level.
What to check if Plesk's Let's Encrypt extension isn't visible
If the Let's Encrypt extension doesn't appear in your Plesk installation, it may need to be installed separately through the Extensions catalog first — most current Plesk versions include it by default, but older installations or specific hosting-provider configurations occasionally have it removed or hidden from the standard interface.
How Plesk handles wildcard certificates through its Let's Encrypt integration
Plesk's Let's Encrypt extension supports wildcard certificate issuance directly through its interface when your DNS is managed through a supported provider with API access configured, automating the DNS-01 validation wildcard certificates require without needing manual DNS record management.
What Plesk's Security Advisor recommends beyond the basic certificate installation
Plesk's built-in Security Advisor typically surfaces additional recommendations around HSTS, TLS version restrictions, and cipher suite hardening once a basic certificate is installed — worth reviewing as a complete checklist rather than treating certificate installation alone as a finished configuration.
How to install a certificate purchased elsewhere rather than through Plesk's Let's Encrypt integration
For a paid certificate purchased directly from a CA rather than through Plesk's built-in Let's Encrypt extension, the SSL/TLS Certificates panel includes an upload option accepting your certificate, private key, and CA bundle files directly, alongside the automated Let's Encrypt option.
Why Plesk's per-domain SSL settings need individual review on a multi-domain server
Each domain hosted under Plesk maintains its own independent SSL/TLS configuration — confirming certificate status and settings for every domain individually, not just the primary one, ensures a multi-domain Plesk server doesn't have one or more domains still running without proper HTTPS.
What to check if certificate renewal fails silently on Plesk
Plesk's Let's Encrypt extension logs renewal attempts within its own interface — checking this log directly, rather than only noticing a problem once a certificate has actually expired, catches a renewal failure (commonly a DNS or firewall issue blocking validation) while there's still time to fix it before expiry.
Why keeping Plesk itself updated matters for certificate-related features specifically
Plesk periodically updates its Let's Encrypt extension and broader SSL/TLS handling to reflect current CA/Browser Forum requirements and browser expectations — running an outdated Plesk version risks missing important fixes or facing compatibility issues with current CA validation requirements.
A closing note on Plesk's overall approach to certificate management
Plesk's combination of built-in Let's Encrypt automation, a clear manual upload path for paid certificates, and Security Advisor's ongoing recommendations covers the large majority of what a typical Plesk-hosted site needs, with manual OpenSSL work rarely necessary outside of unusual, specific requirements.
A final practical tip worth adding to your routine
Beyond the extension itself, checking Plesk's own event and mail notification settings ensures you actually receive alerts about any certificate-related issue Plesk detects, rather than needing to proactively check the panel yourself to notice a problem.