Skip to content

TLS certificates

Every domain has a TLS mode. The default, Automatic, needs nothing from you: Caddy on your server obtains and renews a Let’s Encrypt certificate as soon as DNS points at it.

Mode Value How the certificate is obtained Publicly trusted
Automatic (Let’s Encrypt) auto ACME HTTP-01 / TLS-ALPN-01 on ports 80/443 Yes
DNS-01 (wildcard) dns ACME DNS-01 through a Cloudflare API token Yes
Custom certificate custom You upload certificate, private key and optional chain Depends on your CA
Internal CA internal Caddy’s local CA (self-signed) No
Off (HTTP only) off none —

Change the mode per domain in the domains table under Settings → Networking.

Requirements:

  • DNS for the name points at the server (or load balancer), and records are not proxied.
  • Ports 80 and 443 are reachable from the internet (the server firewall allows them by default for app, web and lb servers; check your cloud provider’s security groups).

The ACME account e-mail is FALAK_ACME_EMAIL (set by the installer from --email). FALAK_ACME_CA overrides the ACME directory (for example Let’s Encrypt staging).

Use DNS-01 for wildcard names (*.example.com), for servers not reachable on port 80, or behind a proxy.

  1. Create a Cloudflare API token with Zone → DNS → Edit for the zone (at least 20 characters).
  2. In Settings → Networking, under DNS providers, click Add, choose Cloudflare, name it and paste the token. Tokens are shared by the organization (permission edge.dns.manage, admins).
  3. Set the domain’s TLS mode to DNS-01 and pick the credential.

Upload under Settings → Networking → Custom certificates: the certificate (PEM), the private key and an optional chain, up to 64 KiB each. Falak installs it on every server routing the site. Then set the domain’s TLS mode to Custom and select it. You are responsible for renewals.

Caddy issues a certificate from its own local CA. Browsers show a warning unless you trust that CA. Use it for private networks only. Health checks do not verify internal-CA certificates.

  • edge.certificate_failed (critical) when installing a certificate fails.
  • edge.certificate_installed (info) when it recovers.
Symptom Fix
Certificate stays pending Run the DNS check. The name must point at the server and not be proxied. Ports 80/443 must be open in your cloud firewall.
Let’s Encrypt rate limit errors Too many certificates for the same registered domain (common on shared sslip.io names). Use your own domain.
Browser warns about the certificate The domain uses Internal CA, or a custom certificate without its chain.