---
title: "How do I use multiple SSL certificates on a site?"
url: "https://ploi.io/documentation/ssl/how-do-i-use-multiple-ssl-certificates-on-a-site"
published: "2026-09-29"
last_updated: "2026-09-29"
---

# How do I use multiple SSL certificates on a site?

A site can hold more than one SSL certificate, but only one serves traffic at a time. That certificate has the **Active** badge in the certificate list. The others stay installed next to it, each with its own files on the server, and you switch between them with **Activate**. This lets you prepare a replacement before you take the old certificate out, without downtime.

### Where to find it

Open the site and click **SSL** in the sidebar. You add certificates in the **New certificate** card. The list below it shows every certificate with its type, its domains, the path of the certificate file and the number of days until it expires.

### Adding another certificate

You add it the same way as the first one, as a [Let's Encrypt](/documentation/ssl/how-do-i-request-a-letsencrypt-certificate) or [ZeroSSL](/documentation/ssl/how-do-i-request-a-zerossl-certificate) certificate, or as an existing certificate you paste in. When the site already has an active certificate, Ploi installs the new one and leaves the site on the current certificate. The log then says the certificate was installed but not activated. When the site has no active certificate, the new one becomes active right away.

You can request a Let's Encrypt or ZeroSSL certificate for exactly the same domains as an existing one. Every certificate gets its own files, so they never overwrite each other.

### Switching to another certificate

Click **Activate** next to the certificate you want to use. Ploi first checks that its certificate and key files are on the server, and stops without touching anything if they are missing. It then points the site's NGINX configuration at the new files, writes the HTTP to HTTPS and www redirects again and reloads NGINX. The switch takes a few seconds. A reload lets NGINX finish open connections, so visitors don't notice it.

The button only shows for certificates that have finished installing. Signing requests and certificates requested through a load balancer can't be activated.

### When this is useful

- **Replacing an uploaded certificate before it expires.** Paste the new one with **Install existing certificate**, activate it, then delete the old one.
- **Moving from a custom certificate to Let's Encrypt.** Request the Let's Encrypt certificate, wait until it has installed, then activate it.
- **Covering new domain aliases.** Request a new certificate, use **Add aliases** to put the aliases in the domain field, activate it and delete the old certificate.
- **Changing how the certificate is validated.** Request the same domains again through a DNS provider instead of HTTP validation, or with ZeroSSL instead of Let's Encrypt, and activate the new one.

### Renewal

Let's Encrypt certificates renew automatically, whether they are active or not. Every server runs `certbot renew` once a day between 01:00 and 07:00. Certbot renews each certificate that expires within 30 days and Ploi reloads NGINX afterwards. Delete the certificates you no longer use, otherwise they keep renewing.

Certificates you pasted in yourself don't renew. Ploi checks their expiry date every day and shows it in the list, so replace them in time with the steps above.

### HTTP/3

HTTP/3 belongs to the certificate, not to the site. You switch it on with **Use HTTP/3** when you request a Let's Encrypt or ZeroSSL certificate, and you can't change it later. Activating a certificate without HTTP/3 turns HTTP/3 off for the site, so tick **Use HTTP/3** on the replacement if you want to keep it. Pasted certificates can't use HTTP/3. More about the requirements is in [Setting up HTTP/3 with NGINX on Ubuntu](/documentation/server/setting-up-http3-with-nginx-on-ubuntu).

### Deleting a certificate

You can delete any certificate that isn't active. Ploi revokes a Let's Encrypt certificate before it removes it. To delete the active certificate while the site has others, activate one of the others first. When you delete the last certificate of a site, Ploi removes the HTTPS configuration and the site serves plain HTTP again.

### Tenants

[Tenants](/documentation/domains/how-does-the-tenants-feature-work-for-sites) work the same way. Every tenant has its own certificates with one of them active. Open **Tenants** in the site sidebar and expand **Certificates** on the tenant to activate or delete one. Ploi doesn't start a new request for a tenant while another request for that tenant is still running.

You can also switch certificates through the API with the [activate certificate](https://developers.ploi.io/certificates/activate-certificate) endpoint.