DirectAdmin has a built-in ACME client, so a Let's Encrypt certificate is a few ticks on one page and renews itself afterwards. What trips people up is not the page but the prerequisites: DNS that does not point at the server yet, a mail. name nobody created a record for, or a CAA record left over from a previous host. This guide goes through the request, the options worth ticking, wildcards, forcing HTTPS, and the failures we see most.
Before you request
Let's Encrypt has to reach the domain over HTTP to prove you control it, so the domain's A record (and www) must already point at this server and port 80 must be open. If you are still moving from another host, do everything else first and come back to this step after DNS has changed; requesting early only produces an error.
On the server side, the ACME client must be built and enabled. On any recent install it is, and the admin can confirm with:
da config-get letsencrypt
cd /usr/local/directadmin/custombuild && ./build letsencryptA 1 from the first command means the option is on; the second updates the client to the current version.
Request the certificate
User Level → Account Manager → SSL Certificates. The page lists the ways a certificate can be provided; choose the free automatic certificate from the ACME provider, which is Let's Encrypt by default.
Below that is a list of names to include, each with a checkbox: the bare domain, www, mail, ftp, pop, smtp and webmail, plus any alias pointers on the domain. Tick the ones that have DNS records. The bare domain and www are the minimum; mail matters because it is what email clients connect to, and a certificate that does not include it produces a warning in every mail app. Any name you tick without a matching DNS record fails validation and blocks the whole request, so untick what does not resolve rather than guessing.
Choose the key type and save. DirectAdmin queues the request, the task queue runs it within a minute, and the page reports the result. A green message means the certificate is installed and Apache has been reloaded; nothing else is needed.
Since 1.709, changing the key type on this page re-issues the certificate on the next run rather than waiting for renewal, which is useful if you want to move a domain to ECDSA keys.
Force HTTPS
A certificate does not redirect anyone. Open Account Manager → Domain Setup, click the domain and tick Force SSL with https redirect. Every HTTP request is then answered with a 301 to the same URL over HTTPS, before anything in .htaccess runs. For WordPress, also set the site address in Settings → General to https://, or the site keeps generating HTTP links that redirect on every click.
Wildcard certificates
A wildcard certificate, *.example.com, covers every subdomain and is the answer when you have many or when they come and go. Let's Encrypt requires DNS validation for wildcards, which DirectAdmin does automatically as long as this server hosts the domain's DNS zone: it writes the validation TXT record, waits for it to be visible and removes it afterwards. In 1.709 that wait is shorter because the client checks only the authoritative nameservers instead of waiting for a public resolver to catch up.
Tick the wildcard option on the SSL Certificates page and keep the bare domain ticked as well, since *.example.com does not cover example.com itself. If DNS lives elsewhere, Cloudflare for instance, the panel cannot write the record and the wildcard request fails; use single names instead, or move DNS to the server.
Renewal
Certificates last 90 days and DirectAdmin renews them from its daily task well before expiry, using the same names and settings as the original request. The one way renewal breaks is when a name on the certificate stops resolving, typically an alias pointer that was dropped or a mail. record deleted during a DNS tidy-up. The renewal then fails for the whole set, the admin receives a message, and the fix is to open the SSL page and untick the missing name.
Common failures
Invalid response or 404 during validation. DNS points somewhere else, usually the old host. Check with dig +short example.com from outside the server and wait for the record to change.
A mail. or www name fails. That subdomain has no A record. Add it in DNS Management or untick it.
CAA record forbids issuance. The domain has a CAA record allowing a different certificate authority, often left by a previous host. Add 0 issue "letsencrypt.org" or remove the restriction.
Rate limit exceeded. Let's Encrypt allows a limited number of identical certificates per week. Fix the cause before retrying.
The panel on port 2222 still warns. That is the server hostname's certificate, a separate job for the admin covered in the first steps after installing.
Errors from the ACME client are recorded in /var/log/directadmin/errortaskq.log, which the admin can read when the message on the SSL page is not enough.
The command line
The panel calls a script the admin can also run directly, which is faster when fixing several domains:
/usr/local/directadmin/scripts/letsencrypt.sh request example.com 4096
/usr/local/directadmin/scripts/letsencrypt.sh renew example.com 4096request uses the name list saved for the domain on the SSL page. For the server's own hostname, request_single server1.example.com 4096 issues a certificate for that one name, which is how the panel, webmail and phpMyAdmin get theirs.
The certificate files for a user's domain sit under /usr/local/directadmin/data/users/<user>/domains/ as <domain>.cert, <domain>.key and <domain>.cacert. If the domain has just been added, the domain setup guide covers the DNS that needs to exist before any of this works.