Skip to content
Generate SSL Certificates

Generate SSL Certificates

Every server in your fleet can carry its own SSL certificate, issued and renewed from the panel. Players connect over HTTPS, the panel is served encrypted, and the certificate lifecycle is not your problem to remember.

Before generating: a domain

Certificates are issued to domain names, so the server needs one first — set it on the server’s settings and point its DNS at the server’s IP. The Generate SSL button stays disabled until a domain is configured; that is the panel refusing to start a request that cannot succeed.

Generate

On the server’s edit screen, Generate SSL starts the issue and shows progress live, phase by phase, until the certificate is installed and the web server reloads with it. The certificate’s serial and subject are displayed on the server screen afterwards, so what is actually being served is never a mystery.

Each server holds its own certificate for its own domain — a fleet of load balancers under lb1., lb2., lb3. of your domain each get theirs, issued from the same screen.

Renewal is automatic

A daily job renews certificates before they expire, fleet-wide, and can notify you when a renewal happens. There is nothing to schedule and no morning where half your players refuse to connect over an expired certificate.

Removing SSL safely

Remove SSL takes a server back to its self-signed state cleanly: the web server configuration is restored and validated before anything reloads, and the certificate is retired properly. Removal is deliberate — the renewal job will not resurrect a certificate you removed on purpose.

With delivery encrypted, the next thing to protect is your data — backups.