ConceptsNetworking, domains & TLS
The life of a certificate
Ferry requests, renews and tries again each certificate with no action from you.
New hostname. The proxy routes a new hostname. The hostname gets its certificate in seconds.
1 / 5
See the certificates
Terminal
$ ferry certificatesHOST SERVICE CERTIFICATEshop.example.com shop issued expires in 2moIn the dashboard, open Server → Domains. The list has each hostname with the state of its certificate.
| State | Meaning |
|---|---|
| Issued | The host has its certificate. Ferry shows the date when it ends. |
| In request | Ferry requests the certificate now. |
| Failed | The request failed. Ferry shows the cause and the time of the next try. |
A host with no certificate yet answers HTTPS with a self-signed certificate. Thus the TLS handshake never fails hard.
The ACME account and the certificates are in <data-dir>/certs. The private keys have the mode 0600. Ferry loads them again at startup.