Requirements and responsibilities
Identify the exact hostname, expected server address, DNS owner and certificate provider. A domain must resolve to the intended site before a free certificate can be issued; recent DNS changes may take time.
Enable HTTPS and configure SSL certificates in xCloud · Fix failed free SSL in xCloud
Separate certificate issuance or renewal failure from a valid certificate with mixed-content or WordPress URL problems. Record the actual browser error and certificate name, issuer and expiry.
Troubleshoot SSL issues in WordPress · Fix failed free SSL in xCloud
Have an authorized site operator for SSL changes and an owner for DNS/firewall changes. Confirm whether Cloudflare or a custom certificate is in use before attempting a free certificate reinstall.
Enable HTTPS and configure SSL certificates in xCloud · xCloud agent capability boundaries
Identify the registrar account owner as well as the xCloud site and DNS owners. The registrar controls registration expiry, payment method and renewal notices; an SSL certificate renewing successfully does not renew the domain name. Record the observed registrar status separately from public RDAP data, which may omit or lag account details.
ICANN domain renewal guidance · ICANN Lookup FAQ for registration dates
Illustrative situation
Illustrative scenario: before a seasonal campaign, a site owner checks that the primary and www hostnames still reach the intended xCloud site, serve valid HTTPS and retain an active domain registration. The SSL operator can repair a failed certificate, while the separate registrar owner confirms expiry, auto-renew and billing contact without buying a renewal during this review.
Choose the approach
Start with non-destructive observations: DNS resolution, xCloud SSL status and the certificate actually served at the final hostname. A dashboard badge alone does not prove what every visitor receives.
Fix failed free SSL in xCloud · Troubleshoot SSL issues in WordPress
If DNS and network reachability are correct but xCloud free SSL remains failed, use the supported site SSL control or discovered certificate tool only for the exact hostname and after recording the existing state.
Fix failed free SSL in xCloud · xCloud agent capability boundaries
Treat domain registration, authoritative DNS and the served TLS certificate as three different status checks. If the domain registration is near expiry or auto-renew is uncertain, the registrar owner resolves the account state; xCloud SSL renewal cannot fix that dependency.
ICANN domain renewal guidance · ICANN Lookup FAQ for registration dates · Enable HTTPS and configure SSL certificates in xCloud
Dashboard and application procedure
Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.
Step 1 of 6
Confirm live DNS and certificate identity
- Where
- Browser, DNS lookup and xCloud site view; connected MCP reads
- Permissions
- Authorized owner or administrator for the named team, site and application.
- Inputs
- Full hostname, current DNS answers, xCloud site/server, SSL provider and browser error.
- Action
- Record the intended primary and www hostnames and exact xCloud site ID. Compare authoritative/public DNS answers with the expected server and inspect the certificate actually served: name, issuer, not-before and expiry.
- Expected result
- A dated mapping of domain, target site, DNS response and served certificate.
- Verify
- Check both hostnames externally and record whether each response matches the intended target.
- If it fails
- If a hostname resolves elsewhere, involve the DNS owner before renewing a certificate on the wrong site.
Sources: Enable HTTPS and configure SSL certificates in xCloud · Fix failed free SSL in xCloud
Step 2 of 6
Check renewal prerequisites and route
- Where
- xCloud SSL/site controls and server firewall view
- Permissions
- Authorized owner or administrator for the named team, site and application.
- Inputs
- DNS records, HTTP/HTTPS reachability, proxy/CDN mode and recent changes.
- Action
- Inspect certificate status and whether ports 80/443 and the expected domain path are reachable. Identify CDN, firewall and redirect owners. Record the configured renewal path without triggering a new certificate request.
- Expected result
- A known certificate renewal route and any blockers.
- Verify
- Compare live HTTPS with xCloud certificate status and the chosen certificate provider.
- If it fails
- If reachability or DNS blocks issuance, assign that layer to its owner before attempting SSL repair.
Sources: Fix failed free SSL in xCloud · Enable HTTPS and configure SSL certificates in xCloud
Step 3 of 6
Repair only a confirmed certificate failure
- Where
- Site → SSL settings or connected MCP SSL certificate operations
- Permissions
- Authorized owner or administrator for the named team, site and application.
- Inputs
- Exact hostname, current certificate type/status, provider and proposed renew/reinstall action.
- Action
- If the certificate is failed or expired after DNS and reachability checks, have the authorized owner use the supported exact-host renewal or provider procedure with approval. If it is valid, leave SSL settings unchanged.
- Expected result
- Either a documented healthy certificate or a targeted repair result.
- Verify
- Wait for terminal status and inspect the served chain, hostname and expiry from outside the dashboard.
- If it fails
- If renewal fails, retain the previous valid configuration where possible and escalate with DNS and issuance evidence.
Sources: Fix failed free SSL in xCloud · Enable HTTPS and configure SSL certificates in xCloud · xCloud agent capability boundaries
Step 4 of 6
Check secure WordPress pages and redirects
- Where
- WordPress Settings and browser developer tools
- Permissions
- Authorized owner or administrator for the named team, site and application.
- Inputs
- Final HTTPS URL, mixed-content requests, WordPress/site URL settings and redirects.
- Action
- Open the public page, wp-admin and a representative form or checkout path over HTTPS. Test agreed www/non-www redirects and canonical links; if the certificate is valid but the page warns, inspect mixed-content or WordPress URL settings before a narrow change.
- Expected result
- The intended canonical HTTPS routes and business task work without mixed content.
- Verify
- Compare public browser results across both host variants and a limited customer session.
- If it fails
- If redirects loop or assets load over HTTP, reverse only the identified URL or proxy change and retest.
Sources: Troubleshoot SSL issues in WordPress · Enable HTTPS and configure SSL certificates in xCloud
Step 5 of 6
Record certificate renewal readiness
- Where
- Production browser and xCloud SSL status
- Permissions
- Authorized owner or administrator for the named team, site and application.
- Inputs
- Affected hostnames, key customer paths, certificate expiry and monitoring owner.
- Action
- Record the live certificate expiry, provider, alert contact and person who checks failed renewal notices. Repeat external checks for every required hostname after DNS, CDN or site changes.
- Expected result
- A named SSL renewal owner with current evidence.
- Verify
- Ask the owner to locate the certificate expiry and alert route without relying on a dashboard badge alone.
- If it fails
- If the alert contact is stale, update ownership and schedule a new external check.
Sources: Enable HTTPS and configure SSL certificates in xCloud · Fix failed free SSL in xCloud
Step 6 of 6
Verify domain registration renewal with its owner
- Where
- Registrar account and public ICANN Lookup as a cross-check
- Permissions
- Authorized domain registrant or registrar account owner with read access; no purchase or account change in this review.
- Inputs
- Domain name, registrar account, registration expiry, auto-renew status, payment/contact owner and reminder route
- Action
- Ask the registrar owner to inspect the account’s exact expiry date, auto-renew setting, payment method validity and reminder contact. Cross-check the registrar and any public expiry date with ICANN Lookup, noting that public registration data may be unavailable or differ from billing state. Record who will act before expiry; do not purchase or renew in this verification task.
- Expected result
- A separate registration-renewal status and named accountable owner.
- Verify
- Have the registrar owner confirm the account evidence and reminder recipient; compare public lookup only where available.
- If it fails
- If expiry is near, account access is missing or auto-renew cannot be verified, escalate to the registrant and registrar promptly; an SSL change cannot extend registration.
Sources: ICANN domain renewal guidance · ICANN Lookup FAQ for registration dates
Maintenance
Review the served certificate, public DNS and registrar account expiry as separate dates. Recheck after DNS, CDN or domain changes; the xCloud site owner tracks SSL notices while the registrant tracks renewal reminders and payment continuity.
Enable HTTPS and configure SSL certificates in xCloud · ICANN domain renewal guidance
After WordPress/plugin changes, spot-check mixed content and customer paths on HTTPS; a valid certificate does not prove application behavior.
Recovery decisions
If a certificate operation fails, retain the previous valid configuration where possible and escalate with DNS, reachability and error evidence. Do not repeatedly replace an unrelated custom certificate.
Fix failed free SSL in xCloud · xCloud agent capability boundaries
If an application URL change causes loops or breaks checkout, revert that specific WordPress/proxy setting under change control and test the key paths again.
If the domain registration has expired or renewal status is disputed, contact the registrar account owner and registrar; do not repeatedly replace the certificate or restore WordPress data to solve a registration problem.
AI handoff
Connect xCloud MCP in an agent client and select the intended team. Discover the current tools, schemas and scopes. Use reads for inventory; present exact site, server, domain, cost, interruption and data impact before each approved write. Use returned dashboard_url values for manual work. The packaged REST fallback accepts GET requests only; never use it for writes.
Supported scope
- Confirm requirements and inspect resources mcp · read
Discover the connected profile and operation schema first; only teams granted to the connection are visible.
Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.
Operation identifiers and scopes to discover
teams.index, servers.show, sites.show
Scopes: read:servers, read:sites
xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
- Inspect and repair site certificates mcp · write
Discover the connected schema; certificate and renewal actions are writes. DNS, ownership, firewall and browser observations require separate checks.
Checkpoint: Identify exact hostname and existing certificate, confirm the proposed action, then validate chain, name, expiry and live HTTPS.
Operation identifiers and scopes to discover
sites.ssl, sites.sslCertificates, sites.sslCertificates.create, sites.ssl.renew
Scopes: read:sites, write:sites
xCloud SSL certificate operations · Enable HTTPS and configure SSL certificates in xCloud · Fix failed free SSL in xCloud
- Configure and test application behavior app · manual
xCloud hosting operations do not configure WooCommerce checkout, n8n workflows, Nextcloud sharing policy or application users.
Checkpoint: An application administrator verifies each real business journey and records observed outcomes.
WooCommerce testing orders · n8n Webhook node and test/production URLs · Nextcloud file sharing administration · xCloud agent capability boundaries
- Verify domain registration renewal status app · manual
Only the domain registrant or registrar account owner can confirm account expiry, auto-renew, payment and reminders; xCloud SSL tools do not renew domain registration.
Checkpoint: Record expiry, auto-renew evidence and accountable contact without purchasing or changing the registration.
ICANN domain renewal guidance · ICANN Lookup FAQ for registration dates
Copyable agent brief
Manual checkpoints
- Confirm DNS and firewall ownership.
- Inspect browser certificate and mixed content.
- Approve exact SSL repair and validate customer paths.
- Registrar owner checks domain expiry, auto-renew, payment validity and reminder contact in the registrar account; no renewal purchase is made by this guide.
Feature coverage
- diagnosis (covered): Separates hostname, DNS and served certificate. Confirm live DNS and certificate identity
- prerequisites (covered): Checks public reachability and proxy path. Check renewal prerequisites and route
- certificate (covered): Uses supported exact-host repair. Repair only a confirmed certificate failure
- application (covered): Resolves mixed-content or URL faults. Check secure WordPress pages and redirects
- acceptance (covered): Tests required hostnames and business flows. Record certificate renewal readiness
- domain registration renewal (covered): Registrar owner checks expiry, auto-renew, payment and reminder contact separately from TLS. Verify domain registration renewal with its owner
Sources
- Enable HTTPS and configure SSL certificates in xCloud
- Fix failed free SSL in xCloud
- Troubleshoot SSL issues in WordPress
- xCloud agent capability boundaries
- ICANN domain renewal guidance
- ICANN Lookup FAQ for registration dates
- xCloud MCP documentation and connection profiles
- xCloud SSL certificate operations
- WooCommerce testing orders
- n8n Webhook node and test/production URLs
- Nextcloud file sharing administration