- Free SSL installs itself automatically.
- A purchased certificate does not โ it needs a CSR, a validation step, and a manual install.
- Here is the exact sequence.
How to Install a Paid SSL Certificate on Your Nepal-Hosted Website: Step-by-Step
The free SSL certificate that ships with WebsNP hosting installs and renews itself with zero action from you. A purchased OV, EV, or wildcard certificate is different: it requires a specific manual sequence involving a Certificate Signing Request, a validation wait, and an installation step. None of it is difficult once you know the order, but doing it out of order is where most installation problems come from.
Step 1: Generate a Certificate Signing Request (CSR)
A CSR is a small encoded file your server generates that contains your domain and organization details, and it's what you submit to the certificate authority to request the certificate. Generate it from your hosting control panel's SSL/TLS section (in cPanel, under SSL/TLS > Generate a Certificate Signing Request), entering your exact legal business name and domain. Getting these details wrong is the single most common cause of a certificate being issued with mismatched information and needing to be reissued.
Step 2: Submit the CSR and Complete Validation
Paste the generated CSR into the order form when purchasing the certificate. For OV and EV certificates, the certificate authority will then contact you or your business registration records to verify the organization behind the domain, which can take one to several business days depending on the tier. Respond promptly to any verification emails or calls, since a stalled validation step is the most common reason certificate issuance drags on longer than expected.
Step 3: Receive and Install the Certificate Files
Once validated, you'll receive the certificate file itself along with an intermediate certificate bundle (sometimes called a CA bundle) that chains your certificate back to a trusted root authority. Both need to be installed together in your hosting panel's SSL/TLS manager. Missing the intermediate bundle is the most common reason a newly installed certificate shows as untrusted in some browsers even though it looks fine in others.
Get an SSL Certificate WebsNP Installs and Manages For You
WebsNP sells and installs DV, OV, EV, wildcard, and multi-domain SSL certificates for Nepali businesses, priced in NPR with eSewa and Khalti accepted, backed by a Nepali support team on WhatsApp who handle the CSR and activation for you.
See SSL Certificate PlansStep 4: Force HTTPS and Test Thoroughly
After installation, update your site to redirect all HTTP traffic to HTTPS (typically via a rule in .htaccess for Apache-based hosting, or your CMS's SSL settings). Then test the live site using a free tool like SSL Labs' SSL Test, which flags configuration issues like an incomplete certificate chain, expired intermediate certificates, or weak protocol support that a quick visual "padlock check" won't catch.
Step 5: Check for Mixed Content
Once HTTPS is enforced, check every page for mixed content warnings, images, scripts, or stylesheets still loading over plain HTTP, which will show the padlock as broken or with a warning icon even though the certificate itself is installed correctly. This is especially common on sites with older content containing hardcoded http:// links.
What Goes Wrong Without Help
The most common installation mistakes we see: submitting a CSR with a typo in the domain name, forgetting the intermediate certificate bundle, and installing the certificate but never actually forcing the HTTPS redirect, leaving the site accessible over both HTTP and HTTPS with no clear signal to visitors or search engines which is canonical.
WebsNP generates the CSR, submits it, and installs every purchased certificate we sell as part of the purchase, then confirms the redirect and mixed content are clean before calling it done. If you bought an SSL certificate elsewhere and are stuck on installation, message our team on WhatsApp and we'll walk you through it directly.