Skip to main content
The Settings tab has one option: the default key type cPanel uses when generating a new SSL/TLS certificate or CSR. Once set, the Wizard, Certificates generator, Keys, and Requests flows all start with this type pre-selected. Open it from cPanel home → SecuritySSL/TLS CertificatesSettings.
Settings tab with the system default selected

Settings tab with the Default SSL/TLS Key Type radio buttons

Recommendation

Leave Use the system’s default key type selected. It’s the option flagged Recommended and Current in the UI. The system default tracks what cPanel and the broader CA ecosystem consider safe and compatible right now (currently RSA, 2,048-bit on Noxity); we keep it in sync with industry guidance, you don’t need to think about it.

The other choices

Pick one of these only if you have a specific reason: The dropdown takes effect on new certs and CSRs you generate after saving. Existing certs and keys are unchanged.

Save the setting

Click Save. The change is account-wide and persists across logins. To revert, return to this tab and re-select Use the system’s default key type.

Common issues

Some commercial CAs charge extra for ECDSA, some still default to RSA-only on certain product tiers. If the CA refuses, generate an RSA key + CSR for that one cert; you don’t have to change the account-wide default.
Expected. RSA 4096 has roughly 4x the signing work per handshake. Most servers don’t notice; high-traffic origins do. ECDSA P-256 is the better fit if your concern is performance.

Need a hand?

Open a ticket

Best for anything that needs an account check or a config change on our end.

Live chat

Faster for quick questions during business hours.