Skip to main content
Skip to main content

SSL/TLS Certificates

Default SSL/TLS Key Type

The default key type for SSL/TLS certificates and CSRs.

Select this if you don’t know which key type is best for you.
RSA is more compatible with older clients (for example, browsers older than Internet Explorer 11) than ECDSA. New installations of cPanel & WHM ship with this setting.
ECDSA allows websites to support Internet Explorer 11 and retain compliance with PCI standards. secp384r1 is more secure than prime256v1, but may perform slower.
ECDSA allows websites to support Internet Explorer 11 and retain compliance with PCI standards.
RSA is more compatible with older clients (for example, browsers older than Internet Explorer 11) than ECDSA. This is more secure than RSA, 2,048-bit, but will perform slower than RSA, 2,048-bit keys.