Skip to main content

Certificates

HivePaaS serves every domain over HTTPS, with a certificate it gets from Let's Encrypt, and renews before it expires. Most apps need nothing more.

How a domain gets its certificate​

When an app gets a domain, HivePaaS looks for a certificate that covers it: one for the domain itself, or a wildcard for the domain above it. If none does, it asks a certificate authority for one:

  • Without a DNS provider, the authority checks the domain over HTTP, on port 80: the domain must already point at your servers. The certificate is for that domain alone.
  • With a DNS provider, the authority checks a DNS record HivePaaS writes. HivePaaS then asks for a wildcard, such as *.example.com, which covers every other app under it too, and can be issued before the domain points anywhere.

Getting a certificate takes seconds over HTTP, and a few minutes over DNS. Until it arrives, the domain answers with a self-signed certificate, which browsers warn about. A browser that saw it keeps it until it is restarted.

Local names, such as app.localhost or nas.local, get no certificate from an authority: it could never reach them.

Settings​

A project's Domain Settings, in its settings, say how its certificates are obtained:

SettingWhat it does
Automatic CertificatesGets a certificate for each domain nothing covers. Turned off, a domain has one only once you add it.
Default Cert TypeLet's Encrypt, ZeroSSL, Google Trust, or self-signed.
Default Key TypeThe kind of key, such as EC P-256, the default, or RSA 2048.
Default Registration EmailThe email the authority writes to about your certificates.

Authorities​

Let's Encrypt needs no account. ZeroSSL and Google Trust need one: create an SSL Provider in Integrations → SSL Providers, with the account's email, and the EAB KID and EAB HMAC the authority gives you.

Renewal​

A certificate with Auto-renew is renewed from 30 days before it expires, by the certificate renewal job. Its schedule is in Settings → SSL Renewal, with Run Renewal Now to renew what is due at once.

When a certificate cannot be obtained​

The certificate's page in Integrations → SSL Certificates shows why, in its last error. The usual reasons:

  • the domain does not point at your servers yet, or port 80 is closed, for the HTTP check;
  • the DNS provider's credentials cannot write the zone, for the DNS check.

After a failure, HivePaaS waits 6 hours before asking again for the same certificate. Authorities limit how often they issue: Let's Encrypt, to five identical certificates a week, and a redeploy loop asking on every attempt would lock the domain out for days.