PanelicaDocs
panelica.com
Docs / Domains / SSL/TLS Certificates

SSL/TLS Certificates

Panelica 1.0.375 Verified 2026-07-23 Domains

The SSL page manages certificates for every domain from one place: pick a domain on the left, and the right panel shows its certificate, HTTPS settings and issue/renew actions.

Panel locationDomains → SSL/TLShttps://YOUR-SERVER-IP:8443/domains/ssl
 SSL · example.com
Certificate Status Active Let's Encrypt
IssuerLet's Encrypt R11
Valid UntilOctober 21, 2026
Days Until Expiry89
Covered Domainsexample.com · www.example.com
Auto-Renewal / HTTPS Redirect / HSTSEnabled / Enabled / Disabled
Cards below: HTTPS Settings · SSL Auto-Issue (Run auto-issue) · Certificate Actions (Renew / Reissue / Self-Signed) · Upload Custom Certificate

The domain list

The left panel loads the SSL state of every domain and shows it at a glance: a status badge (Active, Expiring, Expired, No Cert, or Disabled when SSL is off for the domain), the certificate provider (Let's Encrypt, Self-signed or Custom) and a days-left counter that turns yellow under 30 days and red under 7. A search box filters the list, and the selected domain is kept in the URL (?domain=...).

Certificate status

The right panel is a stack of cards: certificate status on top, then HTTPS settings, the Auto-Issue card, certificate actions and the custom upload form. The status card shows the issuer, subject, validity dates and a large color-coded days-until-expiry figure. If the certificate covers additional names, they are listed as Covered Domains. A summary row shows whether Auto-Renewal, HTTPS Redirect and HSTS are on. Certificates close to expiry raise a visible warning; for Let's Encrypt certificates with auto-renewal on, the warning notes that renewal will happen automatically.

Auto-Issue: one-click SSL

The SSL Auto-Issue card (its button reads Run auto-issue) is the recommended way to get a certificate. Before doing anything it runs a read-only preflight and shows you the plan in plain words: whether the domain's DNS resolves to this server, whether Cloudflare is in front of it (and proxying), and which issuing strategy the panel intends to use. Then one click runs the whole flow: checking, requesting and installing, in a dialog that stays open until it finishes.

When Cloudflare is detected, an "auto-manage Cloudflare" switch (on by default) lets the panel make the needed DNS adjustments itself. Under Advanced you can override the strategy:

Strategy What it does
Auto The panel picks the best strategy for your DNS situation
Cloudflare Origin Issues a long-lived origin certificate for a Cloudflare-proxied site
Let's Encrypt (standard) Classic validation over HTTP
Let's Encrypt (Cloudflare DNS) Validation via DNS records managed through Cloudflare
Let's Encrypt wildcard A wildcard certificate covering subdomains, via Cloudflare DNS
SAN aggregate One certificate covering several names

On success the dialog shows what was issued and how long it is valid; a "Technical details" section keeps the full decision log for the curious. On failure you get the exact reason and a Try Again button.

Renew, reissue, self-signed

The Certificate Actions card appears while SSL is enabled for the domain. For Let's Encrypt certificates its Renew button requests a fresh certificate; on other providers the button becomes Switch to Let's Encrypt. A self-signed certificate can be generated as well, with the panel warning that browsers will show a trust warning for it. All three actions ask for confirmation first and spell out what will happen: a new certificate is generated, the web server configuration is reloaded, it may take a minute or two, and the site stays accessible throughout.

Let's Encrypt certificates are valid for 90 days; with auto-renewal on, the panel renews them in the final 30 days without any action from you.

Custom certificates

Bought a certificate elsewhere? Upload Custom Certificate takes the certificate file and its private key (plus an optional CA bundle) and installs them for the domain. The form reminds you that the private key must match the certificate, and includes a short troubleshooting list for the classic pitfalls: PEM format, key mismatch and incomplete chains.

HTTPS settings

A settings card holds four checkboxes saved together with Save and Reset buttons: SSL Enabled, Force HTTPS (redirect all HTTP to HTTPS), HSTS with a selectable max-age (from 5 minutes for testing up to 2 years), and Auto-Renew. The last three are only available while SSL is enabled.

Rolling out HSTS? Start with a short max-age and increase it once you are sure every subdomain serves HTTPS correctly. Browsers remember HSTS for the full duration; a long value is hard to walk back.

Permissions

SSL management is a licensed feature (ssl_letsencrypt). Viewing the page, issuing, renewing and uploading certificates are separate permissions; a user without the view permission gets Access Denied, and one without upload rights simply does not see the upload form.

Panelica Documentation · Written and verified against the live panel. · Last verified 2026-07-23 on Panelica 1.0.375