GuidesCustom domains & HTTPS
How Ferry manages certificates
Ferry asks for one certificate for each hostname, keeps it on the disk and renews it.
Request. Ferry asks for a certificate for one hostname.
1 / 4
You do nothing: Ferry does each step.
| Subject | Rule |
|---|---|
| Hostnames | One certificate for each hostname. |
| Storage | <data-dir>/certs/<host>/ in the data directory. Ferry loads the certificates again when ferryd starts. |
| Renewal | It starts 30 days before the expiry. |
| Default hostnames | Under a public domain of the server, <name>.<domain> gets its own certificate, like a custom domain. |
| Local names | localhost, *.localhost, *.local, *.internal, *.test and IP addresses always stay on HTTP. |
Before the certificate is there
| Request | Answer |
|---|---|
| HTTP | Ferry serves the site over HTTP. |
| HTTPS | Ferry serves the site with a self-signed certificate. |
When the hostname has its certificate, each HTTP request gets a 308 redirect to HTTPS.