3 min read Sep 26, 2026

Install a Third-Party SSL Certificate in StackCP

Bought an SSL certificate from another provider? Here's what files you need and how to install the certificate on your FimuroHost Cloud Hosting site.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

The free SSL is enough for most websites, but sometimes you need a certificate from another provider. That might be an Organisation Validated (OV) or Extended Validation (EV) certificate, or your domain's DNS might have to stay with another provider. FimuroHost Cloud Hosting lets you install your own certificate in StackCP.

What you need

Your certificate provider (Certificate Authority) will give you, or you will already have, three pieces of text:

ItemWhat it looks likeWhere it comes from
CertificateStarts with -----BEGIN CERTIFICATE-----Sent by your provider after the certificate is issued
Private KeyStarts with -----BEGIN PRIVATE KEY----- (or RSA PRIVATE KEY)Created at the same time as your CSR. Your provider does not have it
CA Bundle / Intermediate CertificateOne or more BEGIN CERTIFICATE blocksSent by your provider, often as a .ca-bundle or "chain" file

If you haven't ordered the certificate yet, first create a Certificate Signing Request (CSR). See "How to Generate a Certificate Signing Request (CSR)".

Install the certificate

  1. Sign in to your FimuroHost client area at https://app.fimurohost.com.
  2. Go to Services and select the hosting plan for the site.
  3. Click Login to Control Panel / StackCP. StackCP opens for that site without a separate password.
  4. In StackCP, open SSL/TLS (under Security). If you see a package list, go to Manage Hosting → Manage for your site first.
  5. Choose the option to install an external/third-party certificate.
  6. Paste the Certificate, Private Key and CA Bundle into the matching boxes. Include the BEGIN and END lines.
  7. Save.

Installation can take up to 30 minutes. After that, as long as your domain's A records point to your hosting package's IP address, the site will load securely over HTTPS.

Common problems

  • "Key does not match certificate". The private key has to be the one made together with the CSR you sent your provider. If the key is lost, you need to make a new CSR and ask your provider to reissue the certificate. This is usually free.
  • Some devices say the certificate is untrusted. The CA bundle is usually missing or incomplete. Paste the full intermediate chain from your provider.
  • Extra spaces or missing lines. Open the files in a plain-text editor (not Word) and copy everything exactly as it is.

To check that a key and certificate match, compare these two outputs on your own computer. They should be identical:

openssl x509 -noout -modulus -in certificate.crt | openssl md5
openssl rsa -noout -modulus -in private.key | openssl md5

Remember to renew

Unlike the free SSL, a third-party certificate doesn't renew by itself. Industry rules are making certificate lifetimes shorter: from March 2026, the maximum is about 200 days, and it will keep falling in later years. Put a reminder in your calendar, and install the renewed certificate the same way before the old one expires.

Tip: never send your private key by plain email or post it in public. If you need our help installing a certificate, tell us in a ticket and we will advise how to share it safely.

Need help?

If something doesn't work as described, open a support ticket from your FimuroHost client area or message us on WhatsApp at 01818160926. Please include your domain name so we can check your account quickly.

FimuroHost Team

Written by

FimuroHost Team

Technical Writer