FerryDocs

How Ferry manages certificates

Ferry asks for one certificate for each hostname, keeps it on the disk and renews it.

Edit on GitHub

Request. Ferry asks for a certificate for one hostname.

1 / 4
The life of a certificate

You do nothing: Ferry does each step.

SubjectRule
HostnamesOne for each hostname.
Storage<data-dir>/certs/<host>/ in the . Ferry loads the certificates again when ferryd starts.
RenewalIt starts 30 days before the expiry.
Default hostnamesUnder a public , <name>.<domain> gets its own certificate, like a custom domain.
localhost, *.localhost, *.local, *.internal, *.test and IP addresses always stay on HTTP.

Before the certificate is there

RequestAnswer
HTTPFerry serves the site over HTTP.
HTTPSFerry serves the site with a .

When the hostname has its certificate, each HTTP request gets a 308 to HTTPS.

On this page