Automatic HTTPS
Ferry gets one certificate for each public hostname from Let's Encrypt, with the HTTP-01 challenge.
The proxy routes a new hostname. Ferry orders a certificate from Let's Encrypt.
Ferry gets each certificate from Let’s Encrypt, or from a different ACME CA. It uses the HTTP-01 challenge.
Turn it on
ferryd --base-domain apps.example.com \
--proxy-addr 0.0.0.0:80 --https-addr 0.0.0.0:443 \
--acme-email you@example.comThe two options --https-addr and --acme-email are necessary. --https-addr alone does not start an HTTPS listener.
- The HTTP listener must be reachable from the internet on port 80.
- The DNS name must point at the server.
Use port 443
With HTTPS on, Ferry prints public URLs as https://host with no port. Listen on 0.0.0.0:443. Then these URLs work.
Which hosts get a certificate
Each host that the proxy routes, but not a local name and not an IP address:
- the host of each web service and static site, under each domain of the server
- each custom domain
- the dashboard host, if you set one
Each host gets its own certificate. Ferry does not request wildcard certificates.
--acme-staginguses the staging environment of Let's Encrypt: untrusted certificates, generous rate limits.--acme-directorypoints at a different ACME CA.- When you change the CA, Ferry replaces the certificates of the previous CA.
See each option on Server options. For a full server, follow Production setup.