Understanding SSL Certificate Management with  Web Linguist and Managed Hosting Providers   

Web Linguist – AI-Powered Website Translation & Localization

If you're on a managed hosting provider like WPEngine, Kinsta, Flywheel, or Pagely and you've installed Web Linguist using the DNS method, you may have received an email from your host saying it "couldn't renew your SSL certificate." This article explains what's actually happening behind the scenes, why we recommend uploading our certificate to your hosting provider, and — importantly — what does and doesn't break if you choose not to.

This is the informational version. If you just want to know how to upload the certificate, see our step-by-step tutorial.

How a visitor's request actually reaches your site

When someone visits your translated site, their request travels through more places than you might expect. Each hop in the chain establishes its own secure (HTTPS) connection.

  Visitor  →  Cloudflare  →  Web Linguist Reverse Proxy 
   →  Your Hosting Provider                             
    

That means there are actually three SSL certificates involved end-to-end, each managed by a different party:

Connection hop Who manages the SSL certificate
Visitor → Cloudflare Cloudflare (their automatic edge certificate)
Cloudflare → Web Linguist Reverse Proxy Web Linguist (us)
Web Linguist Reverse Proxy → Your hosting provider Your hosting provider (WPEngine, Kinsta, etc.)

The certificate that your visitors actually see and trust is the middle one — between Cloudflare and our reverse proxy. That's the one browsers verify when deciding whether to show the green lock icon on your site. We issue and renew that certificate for you automatically every 60 days. You don't need to do anything for that to work; it happens in the background.

So what is the "upload your cert" recommendation about?

It's about the third hop — between our reverse proxy and your hosting provider.

Your hosting provider also serves its own SSL certificate on the connection coming into its servers (including the one from our reverse proxy). This certificate isn't seen by your visitors, but your hosting provider's internal systems still care about it being valid. Before you started using Web Linguist, your host was almost certainly auto-renewing its own certificate using a system called Let's Encrypt.

That renewal automation typically pre-checks DNS to confirm your domain still points at the host's servers. But once you switched to Web Linguist's DNS mode, your domain stopped pointing directly at your host — it points at us. So your host's renewal pre-check fails, and they send you the "we couldn't renew your SSL certificate" email.

Here's the important part: your host can't renew its own certificate anymore, but the certificate your visitors see is the one we manage. Your site continues to be fully secure for visitors regardless.

To stop those notifications and give your host a valid certificate of its own to serve internally, you can upload our SSL certificate into your host's "Custom SSL Certificate" admin panel. Once you do that, the host happily uses our certificate for its internal connection too, and its renewal-failure alerts go quiet.

What happens if you don't upload the certificate?

This is the most common question we get, so let's be specific.

What will keep working

  • Your site stays online. Your hosting provider will continue to serve your website normally. No downtime.
  • Your visitors still see the green lock icon. Browsers see our Let's Encrypt certificate — fresh, valid, and trusted by every modern browser — when they visit your site. There is no "Not Secure" warning, and your site will not show as "HTTP" or unencrypted. The public-facing certificate remains secure.
  • HTTPS continues to work end-to-end. Every hop in the connection chain is encrypted. Your visitors' experience does not change.
  • We continue to auto-renew our own certificate. The certificate your visitors actually depend on never expires — we handle that every 60 days automatically.

What might be annoying

  • Your hosting provider may keep emailing you "SSL renewal failed." Their internal monitoring sees their own certificate expiring and warns you. The warnings are technically accurate (their certificate is expiring) but no longer meaningful — your visitors don't see that certificate anyway.
  • Your host's internal dashboard may show your SSL as "expired." Same reason — the host is looking at its own certificate, not the one we serve.
  • Some host-side features that depend on a valid local SSL certificate may behave unexpectedly — for example, in-host SSL scanners or certain caching layers that validate certificates before forwarding traffic.

What will not happen

  • ✗ Your host will not stop serving your site.
  • ✗ Your visitors will not see security warnings.
  • ✗ Your site will not show as "HTTP" or "insecure" — the public-facing certificate is from us, and it's always valid.

A note about provider differences

Behavior varies somewhat between managed hosting providers. The vast majority — including WPEngine, Kinsta, Flywheel, and Pagely — will simply send periodic renewal-failure emails but continue serving your site exactly as before. A few less common hosts may be more aggressive about flagging expired certificates or may eventually disable certain optional features that depend on local SSL validation.

If you're on a less common provider, it's worth checking their documentation (or asking their support team) what their behavior is when a custom SSL certificate is uploaded versus when their auto-renewed certificate fails. In all cases we've encountered, uploading our certificate is the cleanest solution: it silences the alarms and lets your host operate normally, while your visitors' experience continues unchanged.

Next step

If you'd like to upload our certificate to your hosting provider, see our step-by-step tutorial here. The process takes about two minutes and only needs to be repeated once every ~60 days when your certificate renews.

✅ Free Multilingual SEO Checklist

Planning to go multilingual?

Grab this free checklist to avoid common mistakes with language setup, URLs, metadata, and more.

👉 Download the SEO Checklist
No opt-in fluff — just what to fix before you translate.

Ready to Reach More Customers?

Join 1,500+ businesses already using Web Linguist to translate their websites, boost SEO, and reach customers in 120+ languages.