Certificates
A newly installed node presents a certificate issued by the cluster’s own certificate authority. Your browser has no reason to trust that authority, so it warns that the connection is not private.
The connection is still encrypted. The warning is about identity, not secrecy — but it also trains people to click through security warnings, which is its own problem.
There are two ways to fix it.
Option 1 — upload a certificate you already have
Section titled “Option 1 — upload a certificate you already have”If your organisation issues certificates, this is the quickest route.
- Open node → System → Certificates.
- Click Upload Custom Certificate.
- Paste the certificate and its private key.
- Click Upload. The web interface restarts briefly and comes back with the new certificate.
Repeat for each node — every node has its own hostname and needs its own certificate.
Delete Custom Certificate reverts a node to the cluster’s own certificate.
Option 2 — automatic certificates
Section titled “Option 2 — automatic certificates”Have each node obtain and renew its own certificate from a certificate authority. Set up once, then it maintains itself.
Step 1 — register, once for the cluster
Section titled “Step 1 — register, once for the cluster”- Sign in as
root@pam. Datacenter → ACME is shown only to that account. - Open Datacenter → ACME.
- Under Accounts, click Add.
- Leave Account Name empty, so the account is named
default. Enter a contact E-Mail address, choose the certificate authority under ACME Directory, and accept its terms. - Click Register.
One account serves every node. Each node uses the account named default. If you gave the
account another name, select it on each node before ordering: in the ACME section of
node → System → Certificates, click Edit next to Using Account, choose the
account and click Apply.
Step 2 — choose how ownership is proved
Section titled “Step 2 — choose how ownership is proved”The authority must confirm you control the domain. Two ways:
| Method | Requires |
|---|---|
| HTTP | The node reachable from the internet on port 80 |
| DNS | A challenge plugin for your DNS provider — no inbound access needed |
Most management networks are not reachable from the internet, which makes DNS the realistic choice.
To set one up: Datacenter → ACME → Challenge Plugins → Add, choose your DNS provider, and supply the API credentials it needs.
Step 3 — request a certificate on each node
Section titled “Step 3 — request a certificate on each node”- Open node → System → Certificates.
- In the ACME section, click Add and enter the node’s fully qualified domain name.
- Choose the challenge method — the plugin from step 2, or HTTP.
- Click Order Certificates Now.
Watch the task output. On success the node’s certificate is replaced and the browser warning disappears.
Renewal then happens automatically. Repeat steps 1–4 for each node.
Reading the certificate list
Section titled “Reading the certificate list”node → System → Certificates lists what the node holds, with issuer, subject, validity dates and alternative names. View Certificate shows the full detail.
On a node that has never been changed you will see the cluster’s own certificate authority and the certificate it issued to this node — the pair responsible for the browser warning.
If something goes wrong
Section titled “If something goes wrong”| What you see | What to do |
|---|---|
| The browser still warns after ordering | You are connecting by IP address or by a name the certificate does not cover. Use the name you requested. |
| The order fails on validation | HTTP: the node is not reachable from the internet on port 80. DNS: check the plugin’s credentials and that the record can be created. |
| The interface is unreachable after uploading a certificate | The certificate and key do not match, or the chain is incomplete. Use console access to the server and delete the custom certificate. |
| A renewal did not happen | Check the ACME account and the challenge plugin’s credentials, then Order Certificates Now manually. |
Still stuck? Contact VM2Cloud support.

