SSL Renewal Tool

SSL Renewal Tool
/

What would you like to do?

Choose an action to get started.

Manage

Recent Certificates

What domain(s) do you need a certificate for?

One domain per line. Use *.domain for wildcards.

A friendly name to identify this certificate. Auto-filled from first domain.

How do you manage DNS for this domain?

Choose how DNS validation will work for the ACME certificate challenge.

No DNS providers configured. .

Add this CNAME record

Add the following record at the DNS provider for :

Type: CNAME
Name:
Value:
Note: For wildcard certificates (*.), the same CNAME record works - no additional record needed.

Verifying DNS records

Checking DNS records for ...

DNS changes can take a few minutes to propagate.

Everything looks good! Click Next to configure your certificate.

Tips:

  • DNS changes can take up to 5 minutes to propagate
  • Check that the CNAME record was saved correctly at the DNS provider
  • Make sure the NS delegation for the zone is active

Assign to Client

Select which client agent should have access to this certificate, or create a new API key.

Or create a new API key:

Selected:

Certificate Configuration

Configure the certificate settings before issuing.

Domains:
DNS:
Client:
(renews when expiry < days away)

Certificate Requested

Certificate issuance is in progress...

This typically takes 30-60 seconds. The page will update automatically.

Certificate issued successfully!

- expires

Certificate issuance failed

Certificates

Loading...
No certificates yet. Click + New Certificate to get started.

DNS Providers

No providers configured yet.

Delegated DNS Entries

These entries are created automatically when you use the Issue Certificate (Delegated DNS) wizard. Each entry represents a CNAME delegation for a customer domain.

No delegation entries yet. Use the Issue Certificate wizard to create one.

Client API Keys

Each client/agent gets their own key. Disable a key to immediately cut off access.

No client keys yet. The master key from .env is currently the only way to authenticate.

Assign Certificate

Assign to a client API key so the client agent can access it.

Add DNS Provider