SSL certificates
In preview
Certificates for every site, mail host and the panel itself. The private key is generated on the server that uses it; only the signing request travels.
Built and lab-tested
- ACME certificates through lego: HTTP-01, and wildcards through DNS-01 against zones hosted in RespireCloud.
- Keys (ECDSA P-256 by default; P-384 and RSA 2048 to 4096) are generated on the node and never leave it.
- Auto-SSL: new sites and aliases are covered automatically, one combined certificate per site.
- Renewals follow the CA's ACME Renewal Information when offered. A failed renewal keeps the current certificate serving and retries with backoff.
- Several CAs in order with rate-limit awareness, including custom CAs with external account binding.
- Upload your own certificate (key match, expiry and chain order checked), create CSRs, issue self-signed certificates for testing, and revoke.
- Deploys to websites, to the mail server (Postfix and Dovecot reloaded) and to the panel's own HTTPS listener.
Coming soon
- DNS-01 through external DNS providers.
- TLS policy (minimum version, ciphers, OCSP stapling) and an HSTS switch.
- Certificate Transparency monitoring and on-demand TLS.
Dedicated screens for this area are being built on the RespireCloud design system. Today every action has a generated form in the panel, is one keystroke away in the command palette (Ctrl K), and is callable through the API.