How to Renew a Certificate Without Downtime
A correctly done renewal shouldn't be visible to visitors at all.
Task-focused guides covering the full lifecycle of certificate management, across every major server platform and format.
A correctly done renewal shouldn't be visible to visitors at all.
Moving the certificate is easy. Moving the private key securely is the part to plan for.
The gateway is almost always the right place to terminate TLS for everything behind it.
Confirm exactly which TLS versions your server accepts, one command per version.
The right certificates, installed in the wrong order — a subtle, specific failure mode.
A checklist before submitting, since removal from the list is slow and painful.
A handful of directives that meaningfully improve revocation-check speed and privacy.
Two directives at the server level, applied globally rather than per virtual host.
TLS doesn't care about the port number — but browsers and URLs need to be told explicitly.
Two separate services, two separate config files, one shared certificate.