SSL certificates

In preview

Certificates for every site, mail host and the panel itself. The private key is generated on the server that uses it; only the signing request travels.

Built and lab-tested

  • ACME certificates through lego: HTTP-01, and wildcards through DNS-01 against zones hosted in RespireCloud.
  • Keys (ECDSA P-256 by default; P-384 and RSA 2048 to 4096) are generated on the node and never leave it.
  • Auto-SSL: new sites and aliases are covered automatically, one combined certificate per site.
  • Renewals follow the CA's ACME Renewal Information when offered. A failed renewal keeps the current certificate serving and retries with backoff.
  • Several CAs in order with rate-limit awareness, including custom CAs with external account binding.
  • Upload your own certificate (key match, expiry and chain order checked), create CSRs, issue self-signed certificates for testing, and revoke.
  • Deploys to websites, to the mail server (Postfix and Dovecot reloaded) and to the panel's own HTTPS listener.

Coming soon

  • DNS-01 through external DNS providers.
  • TLS policy (minimum version, ciphers, OCSP stapling) and an HSTS switch.
  • Certificate Transparency monitoring and on-demand TLS.

Dedicated screens for this area are being built on the RespireCloud design system. Today every action has a generated form in the panel, is one keystroke away in the command palette (Ctrl K), and is callable through the API.

Modules in this area