Skip to content

SSL certificates

How Avaloi gets and renews the SSL certificate for your site, what Cloudflare does in front of it, and what happens if a renewal fails.

Parts of this feature are still being built. The Not yet section lists them.

Every Avaloi site serves HTTPS with a certificate from Let's Encrypt. Avaloi asks for the certificate, installs it on the web server, and renews it before it expires. You do not upload a certificate or manage a key.

How it works

  • Cloudflare sits in front of your site and handles HTTPS for visitors.
  • Cloudflare connects to Avaloi's web server over HTTPS, and Avaloi presents a publicly trusted certificate. That is why Cloudflare's SSL mode can stay at Full (strict).
  • Avaloi renews each certificate when less than 30 days remain. Renewals run once a day, at a time that differs from site to site, so they do not all happen at once.
  • Certificates proved through DNS (your temporary domain, a domain in Cloudflare DNS, and a domain that points _acme-challenge at Avaloi) are renewed by Avaloi's daily renewal check, 30 days before they end.
  • A renewal installs the new certificate only after the web server accepts its settings. If the test fails, the old certificate stays in place.

If a renewal fails

Avaloi retries with a growing wait: 15 minutes, then an hour, then four hours, then longer, up to a day. Your current certificate keeps working while Avaloi retries. Three failures in a row mean the next step needs you. Telling the site owner at that point is not built yet (see Not yet).

The usual causes are a DNS record that no longer points at Avaloi, or a Cloudflare setting that stops Let's Encrypt from reaching the challenge file. Check the domain's DNS records first.

Not yet

  • Avaloi does not email the site owner yet when three renewals fail in a row.
  • A custom domain that Avaloi does not control uses an HTTP challenge. For that to work, Cloudflare must not redirect the challenge path to HTTPS. Turn off the redirect for /.well-known/acme-challenge/ or use DNS only while the certificate is issued.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.