An SSL certificate is a digital document that confirms who a domain belongs to and encrypts the connection between the browser and the server. The protocol in use today is called TLS. The name “SSL” is still used out of habit. The certificate contains the server’s public key. The private key stays only on the server and is not shared with anyone.
SSL encrypts the data between your visitor and your site. It stops form, login, and payment details from being read in transit. Starting with version 154 in October 2026, Chrome asks the visitor for confirmation on the first visit to any public site that does not have SSL. Keep a valid certificate on your site, and a redirect from HTTP to HTTPS, so your visitors do not see that warning. Free SSL is installed automatically on MUVCloud hosting plans.
For most sites, the free SSL on hosting is enough. An automatic DV install covers HTTPS, the lock icon, and the absence of a browser warning. Paid SSL is the better choice when your brand wants the certificate authority’s warranty or liability amount, when you need a Wildcard for many subdomains, or when company identity must be validated with documents (EV). Free SSL is automatic DV in the Let’s Encrypt style. Paid Sectigo/Comodo plans offer a commercial CA and a warranty amount in the same encryption class.
DV (Domain Validation) only confirms control of the domain. Positive SSL is in this group and is usually issued within minutes. A Wildcard covers the main domain and all first-level subdomains with one certificate. EV (Extended Validation) confirms company identity with official documents. Validation can take several business days. The industry also has OV (Organization Validation). The plans sold in the MUVCloud store are DV Positive, Wildcard, and EV. Current browsers do not show a green address bar for EV. The difference is the depth of validation. Encryption strength is in the same class.
| Type | Validation | Typical time | Who it is for |
|---|---|---|---|
| DV (Positive SSL) | Domain | Minutes | Blogs, company sites, small stores |
| Wildcard | Domain (plus subdomains) | Usually fast | Sites with many subdomains |
| EV | Company identity | 5–15 business days | Finance, large stores, higher trust needs |
The server creates a public/private key pair. The certificate authority documents the public key and the domain validation. The private key stays on the server. The visitor’s browser encrypts the session with the public key in the certificate. Only the server that holds the private key can decrypt the traffic.
Public SSL/TLS certificates issued from 15 March 2026 can be valid for at most 200 days. That is the CA/Browser Forum decision SC-081. Browsers and certificate authorities apply it together. A one-year purchase continues as a subscription: before the term ends, the certificate is reissued and installed on the server again. While your subscription is active, MUVCloud helps with that reissue and install. The maximum term drops to 100 days on 15 March 2027 and to 47 days on 15 March 2029.
Yes. Installation of an SSL you buy from muvcloud.com is free. For DV certificates, a typical install takes 10–15 minutes. For EV, company validation can take 5–15 business days. That time is CA validation, not installation. Once validation finishes, installation is completed at no charge as well.
No. Current browsers all support SNI, so more than one SSL certificate can run on the same IP address. A dedicated or extra IP is needed only when a payment provider or an old integration specifically asks for it.
The most common causes: no redirect from HTTP to HTTPS; an image or script loaded with http:// (mixed content); a certificate issued for the wrong name (www versus the bare domain); a missing intermediate certificate (the chain); or an expired certificate. You can force HTTPS in the hosting panel, fix mixed content, and open a support ticket if you need to. The chain and the redirect can be checked together.
Yes. Reissue is normal after a lost key, a server change, or the shorter certificate lifetime set by the CA/Browser Forum. While your subscription is active, MUVCloud helps with reissue and installation on the new server at no charge. When you move, transfer the private key securely. Do not paste the private key into email or a ticket.
A Positive SSL Wildcard issued for *.example.com covers example.com and every first-level subdomain, such as www.example.com and shop.example.com. It does not cover a deeper name such as api.eu.example.com. Those need a separate wildcard for *.eu.example.com. You do not need to reissue the certificate for a first-level subdomain you add later.
For EV, the CA confirms your company’s legal and physical existence from official records and asks an authorized person to approve it. Typical documents are a trade-registry or activity certificate, a letter of authorization, and contact verification. The “5–15 business days” on our card is that validation time. Installation finishes within minutes once validation ends. A complete set of documents shortens the process.
No. Chrome and Firefox have not shown a green address bar for EV certificates since 2019, and Safari since 2018. EV still confirms your company’s identity with official documents. The validated company name is visible when a visitor opens the certificate details.
Yes. The Comodo CA brand was renamed Sectigo in 2018. The “Comodo Positive SSL / Wildcard / EV” products in the store are commercial certificates on Sectigo infrastructure. Browser compatibility and the install process are on the same line.
The warranty amount shown on the cards (for example the higher amount on EV) is a financial liability limit the certificate authority provides under specific conditions. It is not MUVCloud’s hosting SLA or a general insurance policy. It does not increase encryption strength. The details are in the CA’s agreement. Choose DV, Wildcard, or EV for the assurance level you need.
SSL is a service performed immediately in an electronic environment. Under Article 15 of Turkey’s Distance Contracts Regulation, it is outside the right of withdrawal (cayma). That rule applies to consumers in Turkey. It is not US law. If you bought the wrong plan, write to the support team before validation or installation starts. Where we can, we will help with a change.
DV Positive SSL is generally for one FQDN. example.com and www.example.com are different names. On most orders it is issued to cover both, or traffic is redirected to a single name. On a Wildcard, *.example.com covers first-level subdomains. Whether the apex (example.com) is included depends on the product card. Confirm it with support before you order.
Technically yes. Browsers show a “not secure” warning, form and payment data are not encrypted, and virtual POS systems and many integrations require HTTPS. Starting with version 154 in October 2026, Chrome asks visitors for extra confirmation on public sites without SSL. A professional site needs a valid SSL certificate and an HTTPS redirect.
HTTPS is a light ranking signal Google has used for a long time. The main benefit is trust and conversion. On a site without SSL, the browser warning drives visitors away, and measurement and ad tags can break. Expecting “I bought SSL, so I will rank first” is not realistic. Together with the right content, speed, and technical SEO, HTTPS is a basic requirement.
Positive SSL (DV) is enough for one site, one domain, and forms or payments. If you have many subdomains such as blog., shop., and api., you can buy a Wildcard. If you are a bank, a large store, or you need company identity documented, choose EV. Free SSL on MUVCloud hosting is enough for most brochure sites and small sites. Buy a paid plan for the warranty amount, Wildcard coverage, or EV validation.
For small and mid-size stores, DV Positive SSL (or the free DV on hosting) is enough for HTTPS and a virtual POS. The payment page must be HTTPS. If you have many sub-stores or subdomains, choose Wildcard. For corporate trust and high-revenue brands, EV is the usual choice. Encryption strength is in the same class across types. The difference is validation depth and the CA warranty amount.
Yes. Payment providers and banks require valid HTTPS (generally a 2048-bit signature and modern TLS) on the page where card data passes. Sectigo/Comodo DV, Wildcard, and EV certificates at MUVCloud are compatible with browser and bank integrations. Some institutions may state their own brand preference. The technical requirement is usually “a valid certificate from a trusted CA.” If it is unclear, it can be checked together with support.
A CSR (Certificate Signing Request) is a signing request generated on the server. It contains the domain (Common Name), organization details, and the public key. The CA issues the certificate from that request. In cPanel, create it under SSL/TLS, then CSR. In Plesk, generate it from SSL/TLS Certificates. For a Wildcard, the CN is usually *.example.com. Installation of a certificate bought from MUVCloud is free. A CSR can also be created on request. Do not paste the private key into email or a ticket.
For DV Positive and Wildcard, the certificate is usually issued within minutes once domain validation (email or DNS) is complete. MUVCloud typically installs it in 10–15 minutes as well. For EV, CA company validation can take 5–15 business days. Installation is short again once validation ends. The visitor sees the lock when DNS points to the correct server and the HTTP to HTTPS redirect is active.
Even with a certificate installed, a visitor who arrives on http:// can see a browser warning or mixed content. In cPanel, force HTTPS from “Force HTTPS Redirect” or the Domains section, or add a 301 redirect in .htaccess. In WordPress, set the site URLs to https://. After the redirect, mixed content (images or scripts still on http://) should be gone. On MUVCloud hosting we can help with these steps.
A renewal invoice is created before the subscription ends. After payment, the new term starts. Under CA/Browser Forum rules, public certificates are valid for about 200 days, so within a yearly subscription the certificate is reissued and installed on the server again. MUVCloud helps with that reissue and install while the subscription is active. If the term ends and it is not renewed, the browser shows a “not secure / expired” warning. The site may still open technically, but trust and the payment flow break.
If the subscription is active, the certificate can be reissued and installed on the server again. That is free. If the private key was deleted too, a new CSR and a reissue are required. Opening a support ticket, without digging through the panel, is the fastest path. Do not paste the private key into the ticket.
The most common use is website HTTPS: forms, accounts, the cart, and payment pages. Variants of the same technology also provide an encrypted channel for email (TLS on IMAP/POP/SMTP), the control panel, APIs, and some FTP/SFTP cases. The Positive, Wildcard, and EV plans in the MUVCloud store are aimed at web-server installs (Apache, Nginx, LiteSpeed, IIS, and so on).
Look for https:// and the lock icon in the address bar. From the lock you can open “Connection is secure” and the certificate details. If you see http:// or “not secure,” the certificate is missing, expired, issued for the wrong name, or the chain is incomplete. External SSL checkers can also confirm the expiry date and the chain.
No. Positive SSL, Wildcard, and EV plans at MUVCloud all use a 2048-bit signature and modern TLS encryption. The difference between DV and EV is not encryption strength. On EV, the company’s legal identity is validated with documents, and the CA’s warranty amount is higher. The lock in the browser shows HTTPS on all three.
A Wildcard covers only subdomains of the same main domain (*.example.com). It does not cover separate domains such as example.com and other.com with one Wildcard. In the industry that is called SAN / multi-domain. The MUVCloud store currently offers single-domain DV, Wildcard, and EV. If you have several independent domains, you can buy Positive SSL for each, or ask support for a suitable option.
A static site seal is a small trust badge from the CA. Placed on the site, it shows the visitor a graphic or link that the certificate is valid. It does not strengthen encryption. HTTPS is already visible in the lock in the address bar. Positive SSL and Wildcard cards include a static site seal. You can also request the seal code from support after installation.
OV (Organization Validation) also confirms the company name from commercial records, alongside the domain. It is not as deep as EV, but it is more detailed than DV. The MUVCloud store currently offers Positive SSL (DV), Positive Wildcard, and EV. If you want the company name on the certificate and the highest validation, choose EV. DV is enough for most sites.
You are not on your own as your projects grow. Our support engineers are ready 24/7, on several channels, whenever you need them.
