SSL certificates
How Avaloi gets and renews the SSL certificate for your site, what Cloudflare does in front of it, and what happens if a renewal fails.
Parts of this feature are still being built. The Not yet section lists them.
Every Avaloi site serves HTTPS with a certificate from Let's Encrypt. Avaloi asks for the certificate, installs it on the web server, and renews it before it expires. You do not upload a certificate or manage a key.
How it works
- Cloudflare sits in front of your site and handles HTTPS for visitors.
- Cloudflare connects to Avaloi's web server over HTTPS, and Avaloi presents a publicly trusted certificate. That is why Cloudflare's SSL mode can stay at Full (strict).
- Avaloi renews each certificate when less than 30 days remain. Renewals run once a day, at a time that differs from site to site, so they do not all happen at once.
- Certificates proved through DNS (your temporary domain, a domain in Cloudflare DNS, and a domain that points
_acme-challengeat Avaloi) are renewed by Avaloi's daily renewal check, 30 days before they end. - A renewal installs the new certificate only after the web server accepts its settings. If the test fails, the old certificate stays in place.
If a renewal fails
Avaloi retries with a growing wait: 15 minutes, then an hour, then four hours, then longer, up to a day. Your current certificate keeps working while Avaloi retries. Three failures in a row mean the next step needs you. Telling the site owner at that point is not built yet (see Not yet).
The usual causes are a DNS record that no longer points at Avaloi, or a Cloudflare setting that stops Let's Encrypt from reaching the challenge file. Check the domain's DNS records first.
Not yet
- Avaloi does not email the site owner yet when three renewals fail in a row.
- A custom domain that Avaloi does not control uses an HTTP challenge. For that to work, Cloudflare must not redirect the challenge path to HTTPS. Turn off the redirect for
/.well-known/acme-challenge/or use DNS only while the certificate is issued.
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.