When the option is enabled, cPanel → Security → SSL/TLS includes Default SSL/TLS Key Type.
- Open SSL/TLS.
- Select the supported key type you intend to use.
- Save the setting.
The account-level preference overrides the server-level default for certificates and signing requests created for that account. Current cPanel documentation also states that changing the preferred key type triggers an AutoSSL run so installed AutoSSL-issued certificates can be updated to the new key type.