Servers & Hosting (Plesk, CloudPanel, Linux)

CloudPanel Security & SSL Setup

Harden a CloudPanel server and get SSL working correctly across every site on it.

The Problem

A default CloudPanel install needs firewall and access tightening, and SSL issues (mixed content, renewal failures) are common when a site was added before DNS had fully propagated.

About this problem

A fresh CloudPanel install is usable quickly, which also means it's easy to skip the access-hardening step entirely, and SSL issues (mixed content warnings, failed renewals) are common when a certificate was issued before DNS had actually finished propagating to the new server. Both are quick to fix once identified but easy to miss in a rush to get a site live.

This tends to come up right after a migration to CloudPanel, or when a site shows a browser security warning that wasn't there before.

What's Included

What's NOT Included

How It Works

  1. Review current firewall rules and restrict panel access to what's actually needed.
  2. Diagnose SSL issuance or renewal failures by checking DNS propagation and certificate logs.
  3. Find and fix mixed-content sources (hardcoded http:// links/assets) causing browser warnings.
  4. Set up basic brute-force protection on the panel login.
  5. Confirm the site loads with a clean padlock and no console warnings afterwards.

In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.

Frequently Asked Questions

Why does my site show 'mixed content' after moving to CloudPanel?
Usually because some assets (images, scripts, stylesheets) are still hardcoded to load over http:// instead of https://, which browsers flag even when the main page is secure.
Why is my CloudPanel SSL certificate not renewing automatically?
Often a DNS pointing issue or a firewall rule blocking the renewal validation request — Let's Encrypt needs to re-verify domain control on each renewal, same as initial issuance.
Is CloudPanel secure by default?
It's reasonably sensible out of the box, but access restriction and brute-force protection on the login still benefit from a deliberate review, especially right after a fresh install.
How do I fix a 'not secure' warning after installing an SSL certificate?
It's almost always mixed content — the certificate itself is valid, but something on the page is still loading over plain HTTP and needs to be corrected to https://.
Can I use a certificate other than Let's Encrypt in CloudPanel?
Yes, CloudPanel supports installing your own certificate alongside its built-in Let's Encrypt integration, if you have one from elsewhere.
How do I protect the CloudPanel login from brute-force attempts?
Through a combination of firewall rules limiting access and basic rate-limiting/lockout settings — neither is aggressively configured by default.
Please note: the price shown applies to a standard case matching the description above. Every situation is different, and if your request falls outside the normal scope of this service, I will explain this before doing any additional chargeable work. I will never silently turn a small job into an expensive project.
Running into an issue with a service you've already bought, or unsure which one fits your problem? Message me directly on WhatsApp — no ticket system, no bot.