--- title: "Certificates Module Documentation" description: "Documentation for Certificates" --- ## Table of Contents 1. [Navigation & Access](#navigation--access) 2. [Screenshots & Visual Interface](#screenshots--visual-interface) 3. [Module Overview (Technical)](#1-module-overview-technical) 4. [Module Overview (Commercial/Business)](#2-module-overview-commercialbusiness) 5. [Module Overview (End User/Administrator)](#3-module-overview-end-useradministrator) 6. [Configuration Sections](#4-configuration-sections) 7. [Settings Reference](#5-settings-reference) 8. [Common Scenarios & Examples](#6-common-scenarios--examples) 9. [Limitations & Important Notes](#7-limitations--important-notes) 10. [Troubleshooting Tips](#8-troubleshooting-tips) 11. [Glossary](#9-glossary) --- ## Navigation & Access To access the SSL/TLS Certificates module: 1. Log in to the Ring2All Web Portal (`https:///login`). 2. In the left navigation sidebar, expand **Administration**. 3. Under **Network**, click **Certificates** (`/admin/system-settings/certificates`). 4. Click **+ Add Certificate** or select an existing certificate to view or edit public certificates, private keys, Subject Alternative Names (SANs), auto-renewal rules, and service bindings for HTTPS, SIP TLS, and WebRTC WSS (`/admin/system-settings/certificates/:uuid`). --- ## Screenshots & Visual Interface ### SSL/TLS Certificate Registry & Trust Vault Central certificate manager listing installed public certificates, issuance authorities (Let's Encrypt ACME, Custom CA, Self-Signed), expiration horizons, auto-renewal indicators, and active service associations. ![Certificates List](/screenshots/admin/network/certificates-list.png) ### SSL/TLS Certificate Provisioning & Key Enrollment Modal editor for enrolling new X.509 cryptographic pairs, selecting certificate providers, configuring domain SANs, uploading PEM cert chains and RSA/ECC private keys, and designating TLS application roles. ![Certificates Form](/screenshots/admin/network/certificates-form.png) --- ## 1. Module Overview (Technical) ### What Is the Certificates Module? Certificates is an **SSL/TLS certificate management module** that handles certificate lifecycle for HTTPS, SIP TLS, and WebRTC. It supports Self-Signed, Let's Encrypt (ACME), and Custom certificate types with usage assignment and auto-renewal. ### Architecture ``` ┌─────────────────────────────────────────────────────────────────┐ │ Certificates Architecture │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Certificate Definition │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Certificate: Production SSL │ │ │ │ │ │ │ │ Type: Let's Encrypt │ │ │ │ Domain: pbx.company.com │ │ │ │ SANs: sip.company.com, webrtc.company.com │ │ │ │ │ │ │ │ Status: ● Active │ │ │ │ Expires: 2025-04-15 (90 days) │ │ │ │ Auto Renew: ✓ │ │ │ │ │ │ │ │ Usage: │ │ │ │ ├─ ✓ HTTPS │ │ │ │ ├─ ✓ SIP TLS │ │ │ │ └─ ✓ WebRTC │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ Applied to services │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Services Using Certificate │ │ │ │ │ │ │ │ HTTPS (Nginx) │ │ │ │ ├─ Admin panel │ │ │ │ └─ API endpoints │ │ │ │ │ │ │ │ SIP TLS (Telephony Server) │ │ │ │ ├─ Encrypted SIP registrations │ │ │ │ └─ Secure voice traffic │ │ │ │ │ │ │ │ WebRTC (via Nginx Proxy) │ │ │ │ ├─ Browser → wss://domain/ws (Nginx TLS on 443) │ │ │ │ └─ Nginx → ws://127.0.0.1:5066 (Telephony Server local) │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` --- ## 2. Module Overview (Commercial/Business) ### Business Value Certificates provides **secure communications**: | Without Certificates | With Certificates | |----------------------|-------------------| | Insecure HTTP | HTTPS encrypted | | Plain SIP | SIP TLS encrypted | | No WebRTC | Secure WebRTC | | Manual renewal | Auto-renewal | ### Use Cases 1. **HTTPS Web Interface** - Secure admin panel - API encryption 2. **SIP TLS** - Encrypted registrations - Secure voice traffic 3. **WebRTC** - Browser calling via Nginx proxy (wss://domain/ws) - TLS terminated at Nginx, forwarded as plain WS to Telephony Server 4. **Let's Encrypt** - Free certificates - Automatic renewal ### Feature Highlights | Feature | Benefit | |---------|---------| | **Self-Signed** | Quick setup | | **Let's Encrypt** | Free, auto-renew | | **Custom** | Enterprise PKI | | **SANs** | Multiple domains | | **Usage Config** | Per-service assignment | | **Expiry Tracking** | Alerts for renewal | --- ## 3. Module Overview (End User/Administrator) ### What Can You Do? - Create self-signed certificates - Request Let's Encrypt certificates - Upload custom certificates - Configure Subject Alternative Names - Assign certificates to services - Enable auto-renewal - Monitor expiration ### Certificates Interface ``` ┌─────────────────────────────────────────────────────────────────┐ │ Certificates │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Manage SSL/TLS certificates for HTTPS, SIP TLS, and WebRTC │ │ │ │ [+ Create Certificate] │ │ │ │ [🔍 Search certificates...] │ │ │ │ ┌───────────────────────────────────────────────────────────┐ │ │ │ Name │ Type │ Domain │ Expires │ Usage│ │ │ ├──────────────┼─────────────┼─────────────┼─────────┼──────┤ │ │ │ Production │ Let's Enc. │ pbx.co.com │ 85 days │ H S W│ │ │ │ Dev Cert │ Self-Signed │ dev.local │ 364 days│ H │ │ │ │ Enterprise │ Custom │ *.corp.com │ 729 days│ H S W│ │ │ └───────────────────────────────────────────────────────────┘ │ │ │ │ Usage: H=HTTPS, S=SIP TLS, W=WebRTC │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Create Certificate - Self-Signed ``` ┌─────────────────────────────────────────────────────────────────┐ │ Create Certificate │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ ▼ General Information │ │ │ │ Name: [Development Certificate ] │ │ Description: [Local development use ] │ │ Type: [Self-Signed ▼] │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Domain Configuration │ │ │ │ Domain: [dev.local ] │ │ The primary domain name for this certificate │ │ │ │ Alt. Domains: │ │ [+ Add Domain] │ │ - sip.dev.local │ │ - webrtc.dev.local │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Organization Information │ │ │ │ Organization: [My Company ] │ │ Organization Unit: [IT Department ] │ │ City: [New York ] │ │ State/Province: [NY ] │ │ Country: [US ] │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Self-Signed Options │ │ │ │ Key Size: [2048 ▼] (2048, 4096) │ │ Validity Period: [365 ] days │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Usage Configuration │ │ │ │ Use for HTTPS: ✓ │ │ Use for SIP TLS: ✓ │ │ Use for WebRTC: ✓ │ │ Set as Default: ✓ │ │ │ │ [Create Certificate] [Cancel] │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Create Certificate - Let's Encrypt ``` ┌─────────────────────────────────────────────────────────────────┐ │ Create Certificate │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ ▼ General Information │ │ │ │ Name: [Production SSL ] │ │ Type: [Let's Encrypt ▼] │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Domain Configuration │ │ │ │ Domain: [pbx.company.com ] │ │ │ │ Alt. Domains: │ │ - sip.company.com │ │ - webrtc.company.com │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Let's Encrypt Configuration │ │ │ │ ACME Account Email: [admin@company.com ] │ │ Required for certificate notifications │ │ │ │ Challenge Type: [HTTP-01 ▼] │ │ HTTP-01 or DNS-01 │ │ │ │ Auto Renew: ✓ │ │ Renew Before: [30 ] days │ │ │ │ ℹ️ The certificate will be automatically requested from │ │ Let's Encrypt. Make sure your domain is publicly accessible. │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Usage Configuration │ │ │ │ Use for HTTPS: ✓ │ │ Use for SIP TLS: ✓ │ │ Use for WebRTC: ✓ │ │ │ │ [Create Certificate] [Cancel] │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Create Certificate - Custom ``` ┌─────────────────────────────────────────────────────────────────┐ │ Create Certificate │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ ▼ General Information │ │ │ │ Name: [Enterprise Wildcard ] │ │ Type: [Custom ▼] │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Certificate Data │ │ │ │ Certificate (PEM): │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ -----BEGIN CERTIFICATE----- ││ │ │ MIIDxTCCAq2gAwIBAgIJAJJp+C... ││ │ │ -----END CERTIFICATE----- ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ Private Key (PEM): │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ -----BEGIN RSA PRIVATE KEY----- ││ │ │ MIIEpAIBAAKCAQEA0Z3VS... ││ │ │ -----END RSA PRIVATE KEY----- ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ Certificate Chain (CA Bundle): │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ Optional: Paste intermediate CA certificates ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ [Validate Certificate] │ │ ✓ Private key matches certificate │ │ │ │ [Create Certificate] [Cancel] │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Quick Tips > [!TIP] > **Let's Encrypt**: Free, auto-renewing, trusted by browsers. > [!TIP] > **SANs**: Add all needed domains in one certificate. > [!WARNING] > **Private Key**: Keep private keys secure. Never share. --- ## 4. Configuration Sections ### General Information | Field | Description | |-------|-------------| | **Name** | Certificate identifier | | **Description** | Optional notes | | **Type** | Self-Signed, Let's Encrypt, Custom | ### Domain Configuration | Field | Description | |-------|-------------| | **Domain** | Primary domain (CN) | | **Alt. Domains** | Subject Alternative Names | ### Organization (Self-Signed) | Field | Description | |-------|-------------| | **Organization** | Company name | | **Organization Unit** | Department | | **City** | Locality | | **State/Province** | Region | | **Country** | Country code | ### Self-Signed Options | Field | Description | |-------|-------------| | **Key Size** | 2048 or 4096 bits | | **Validity Period** | Days until expiry | ### Let's Encrypt Configuration | Field | Description | |-------|-------------| | **ACME Email** | Notification address | | **Challenge Type** | HTTP-01 or DNS-01 | | **Auto Renew** | Enable auto-renewal | | **Renew Before** | Days before expiry | ### Certificate Data (Custom) | Field | Description | |-------|-------------| | **Certificate (PEM)** | Public certificate | | **Private Key (PEM)** | Private key | | **Certificate Chain** | CA bundle | ### Usage Configuration | Field | Description | |-------|-------------| | **Use for HTTPS** | Web traffic | | **Use for SIP TLS** | SIP encryption | | **Use for WebRTC** | WSS protocol | | **Set as Default** | Default certificate | --- ## 5. Settings Reference ### Certificate Types | Type | Description | Use Case | |------|-------------|----------| | **Self-Signed** | Generated locally | Development, internal | | **Let's Encrypt** | Free, auto ACME | Production, public | | **Custom** | Upload your own | Enterprise PKI | ### Certificate Status | Status | Meaning | |--------|---------| | **Pending** | Being issued | | **Active** | Valid and in use | | **Expired** | Past validity date | | **Revoked** | Manually revoked | | **Error** | Issue/validation error | ### Key Sizes | Size | Security | Performance | |------|----------|-------------| | 2048 | Good | Faster | | 4096 | Better | Slower | --- ## 6. Common Scenarios & Examples ### Scenario 1: Self-Signed for Development 1. Create Certificate 2. Type = Self-Signed 3. Domain = dev.local 4. Key Size = 2048 5. Validity = 365 days 6. Enable all usage 7. Create ### Scenario 2: Let's Encrypt for Production 1. Create Certificate 2. Type = Let's Encrypt 3. Domain = pbx.company.com 4. Add SANs for sip and webrtc 5. Enter ACME email 6. Enable Auto Renew 7. Create (waits for validation) ### Scenario 3: Upload Enterprise Certificate 1. Create Certificate 2. Type = Custom 3. Paste certificate PEM 4. Paste private key PEM 5. Paste CA bundle (if any) 6. Validate (key match check) 7. Configure usage 8. Create ### Scenario 4: Add Domain to Existing 1. Edit certificate 2. Add new Alt. Domain 3. Save 4. (Let's Encrypt re-validates) --- ## 7. Limitations & Important Notes ### Technical Notes > [!NOTE] > **Let's Encrypt**: Domain must be publicly accessible. > [!NOTE] > **Rate Limits**: Let's Encrypt has issuance limits. > [!WARNING] > **Key Security**: Never expose private keys. ### Best Practices 1. **Use Let's Encrypt**: Free and trusted 2. **Auto Renew**: Prevent expiry 3. **Include SANs**: All needed domains 4. **Strong Keys**: Use 2048+ bits 5. **Monitor Expiry**: Watch warning alerts ### Let's Encrypt Requirements | Requirement | Details | |-------------|---------| | Public DNS | Domain must resolve | | Port 80 | HTTP-01 challenge | | No Firewall | Allow Let's Encrypt | | Valid Email | Notifications | --- ## 8. Troubleshooting Tips ### Common Issues | Symptom | Possible Cause | Solution | |---------|---------------|----------| | Let's Encrypt fails | DNS not public | Check DNS resolution | | Key mismatch | Wrong private key | Verify key matches cert | | Browser warning | Self-signed | Use Let's Encrypt | | Expired | Renewal failed | Manually renew | ### Check Certificate ```bash # View certificate details openssl x509 -in cert.pem -text -noout # Check expiry openssl x509 -in cert.pem -enddate -noout # Verify key matches cert openssl x509 -noout -modulus -in cert.pem | openssl md5 openssl rsa -noout -modulus -in key.pem | openssl md5 ``` ### Test HTTPS ```bash # Test certificate chain openssl s_client -connect pbx.company.com:443 -servername pbx.company.com # Check Let's Encrypt validation curl -I http://pbx.company.com/.well-known/acme-challenge/test ``` --- ## 9. Glossary | Term | Definition | |------|------------| | **SSL/TLS** | Encryption protocols | | **PEM** | Certificate text format | | **SANs** | Subject Alternative Names | | **ACME** | Let's Encrypt protocol | | **CA** | Certificate Authority | | **Fingerprint** | Certificate hash | --- *Documentation last updated: January 2026*