Skip to content

Certificates Module Documentation

11 min readUpdated: Sep 26, 2026
View as Markdown
  1. Navigation & Access
  2. Screenshots & Visual Interface
  3. Module Overview (Technical)
  4. Module Overview (Commercial/Business)
  5. Module Overview (End User/Administrator)
  6. Configuration Sections
  7. Settings Reference
  8. Common Scenarios & Examples
  9. Limitations & Important Notes
  10. Troubleshooting Tips
  11. Glossary

To access the SSL/TLS Certificates module:

  1. Log in to the Ring2All Web Portal (https://<domain-or-ip>/login).
  2. In the left navigation sidebar, expand Administration.
  3. Under Network, click Certificates (/admin/system-settings/certificates).
  4. Click + Add Certificate or select an existing certificate to view or edit public certificates, private keys, Subject Alternative Names (SANs), auto-renewal rules, and service bindings for HTTPS, SIP TLS, and WebRTC WSS (/admin/system-settings/certificates/:uuid).

SSL/TLS Certificate Registry & Trust Vault

Section titled “SSL/TLS Certificate Registry & Trust Vault”

Central certificate manager listing installed public certificates, issuance authorities (Let’s Encrypt ACME, Custom CA, Self-Signed), expiration horizons, auto-renewal indicators, and active service associations. Certificates List

SSL/TLS Certificate Provisioning & Key Enrollment

Section titled “SSL/TLS Certificate Provisioning & Key Enrollment”

Modal editor for enrolling new X.509 cryptographic pairs, selecting certificate providers, configuring domain SANs, uploading PEM cert chains and RSA/ECC private keys, and designating TLS application roles. Certificates Form


Certificates is an SSL/TLS certificate management module that handles certificate lifecycle for HTTPS, SIP TLS, and WebRTC. It supports Self-Signed, Let’s Encrypt (ACME), and Custom certificate types with usage assignment and auto-renewal.

┌─────────────────────────────────────────────────────────────────┐
│ Certificates Architecture │
├─────────────────────────────────────────────────────────────────┤
│ │
│ Certificate Definition │
│ ┌──────────────────────────────────────────────────────────┐ │
│ │ Certificate: Production SSL │ │
│ │ │ │
│ │ Type: Let's Encrypt │ │
│ │ Domain: pbx.company.com │ │
│ │ SANs: sip.company.com, webrtc.company.com │ │
│ │ │ │
│ │ Status: ● Active │ │
│ │ Expires: 2025-04-15 (90 days) │ │
│ │ Auto Renew: ✓ │ │
│ │ │ │
│ │ Usage: │ │
│ │ ├─ ✓ HTTPS │ │
│ │ ├─ ✓ SIP TLS │ │
│ │ └─ ✓ WebRTC │ │
│ │ │ │
│ └──────────────────────────────────────────────────────────┘ │
│ │ │
│ ▼ Applied to services │
│ ┌──────────────────────────────────────────────────────────┐ │
│ │ Services Using Certificate │ │
│ │ │ │
│ │ HTTPS (Nginx) │ │
│ │ ├─ Admin panel │ │
│ │ └─ API endpoints │ │
│ │ │ │
│ │ SIP TLS (Telephony Server) │ │
│ │ ├─ Encrypted SIP registrations │ │
│ │ └─ Secure voice traffic │ │
│ │ │ │
│ │ WebRTC (via Nginx Proxy) │ │
│ │ ├─ Browser → wss://domain/ws (Nginx TLS on 443) │ │
│ │ └─ Nginx → ws://127.0.0.1:5066 (Telephony Server local) │ │
│ │ │ │
│ └──────────────────────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────┘

Certificates provides secure communications:

Without Certificates With Certificates
Insecure HTTP HTTPS encrypted
Plain SIP SIP TLS encrypted
No WebRTC Secure WebRTC
Manual renewal Auto-renewal
  1. HTTPS Web Interface

    • Secure admin panel
    • API encryption
  2. SIP TLS

    • Encrypted registrations
    • Secure voice traffic
  3. WebRTC

    • Browser calling via Nginx proxy (wss://domain/ws)
    • TLS terminated at Nginx, forwarded as plain WS to Telephony Server
  4. Let’s Encrypt

    • Free certificates
    • Automatic renewal
Feature Benefit
Self-Signed Quick setup
Let’s Encrypt Free, auto-renew
Custom Enterprise PKI
SANs Multiple domains
Usage Config Per-service assignment
Expiry Tracking Alerts for renewal

3. Module Overview (End User/Administrator)

Section titled “3. Module Overview (End User/Administrator)”
  • Create self-signed certificates
  • Request Let’s Encrypt certificates
  • Upload custom certificates
  • Configure Subject Alternative Names
  • Assign certificates to services
  • Enable auto-renewal
  • Monitor expiration
┌─────────────────────────────────────────────────────────────────┐
│ Certificates │
├─────────────────────────────────────────────────────────────────┤
│ │
│ Manage SSL/TLS certificates for HTTPS, SIP TLS, and WebRTC │
│ │
│ [+ Create Certificate] │
│ │
│ [🔍 Search certificates...] │
│ │
│ ┌───────────────────────────────────────────────────────────┐ │
│ │ Name │ Type │ Domain │ Expires │ Usage│ │
│ ├──────────────┼─────────────┼─────────────┼─────────┼──────┤ │
│ │ Production │ Let's Enc. │ pbx.co.com │ 85 days │ H S W│ │
│ │ Dev Cert │ Self-Signed │ dev.local │ 364 days│ H │ │
│ │ Enterprise │ Custom │ *.corp.com │ 729 days│ H S W│ │
│ └───────────────────────────────────────────────────────────┘ │
│ │
│ Usage: H=HTTPS, S=SIP TLS, W=WebRTC │
│ │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ Create Certificate │
├─────────────────────────────────────────────────────────────────┤
│ │
│ ▼ General Information │
│ │
│ Name: [Development Certificate ] │
│ Description: [Local development use ] │
│ Type: [Self-Signed ▼] │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ ▼ Domain Configuration │
│ │
│ Domain: [dev.local ] │
│ The primary domain name for this certificate │
│ │
│ Alt. Domains: │
│ [+ Add Domain] │
│ - sip.dev.local │
│ - webrtc.dev.local │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ ▼ Organization Information │
│ │
│ Organization: [My Company ] │
│ Organization Unit: [IT Department ] │
│ City: [New York ] │
│ State/Province: [NY ] │
│ Country: [US ] │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ ▼ Self-Signed Options │
│ │
│ Key Size: [2048 ▼] (2048, 4096) │
│ Validity Period: [365 ] days │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ ▼ Usage Configuration │
│ │
│ Use for HTTPS: ✓ │
│ Use for SIP TLS: ✓ │
│ Use for WebRTC: ✓ │
│ Set as Default: ✓ │
│ │
│ [Create Certificate] [Cancel] │
│ │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ Create Certificate │
├─────────────────────────────────────────────────────────────────┤
│ │
│ ▼ General Information │
│ │
│ Name: [Production SSL ] │
│ Type: [Let's Encrypt ▼] │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ ▼ Domain Configuration │
│ │
│ Domain: [pbx.company.com ] │
│ │
│ Alt. Domains: │
│ - sip.company.com │
│ - webrtc.company.com │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ ▼ Let's Encrypt Configuration │
│ │
│ ACME Account Email: [admin@company.com ] │
│ Required for certificate notifications │
│ │
│ Challenge Type: [HTTP-01 ▼] │
│ HTTP-01 or DNS-01 │
│ │
│ Auto Renew: ✓ │
│ Renew Before: [30 ] days │
│ │
│ ℹ️ The certificate will be automatically requested from │
│ Let's Encrypt. Make sure your domain is publicly accessible. │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ ▼ Usage Configuration │
│ │
│ Use for HTTPS: ✓ │
│ Use for SIP TLS: ✓ │
│ Use for WebRTC: ✓ │
│ │
│ [Create Certificate] [Cancel] │
│ │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ Create Certificate │
├─────────────────────────────────────────────────────────────────┤
│ │
│ ▼ General Information │
│ │
│ Name: [Enterprise Wildcard ] │
│ Type: [Custom ▼] │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ ▼ Certificate Data │
│ │
│ Certificate (PEM): │
│ ┌─────────────────────────────────────────────────────────────┐│
│ │ -----BEGIN CERTIFICATE----- ││
│ │ MIIDxTCCAq2gAwIBAgIJAJJp+C... ││
│ │ -----END CERTIFICATE----- ││
│ └─────────────────────────────────────────────────────────────┘│
│ │
│ Private Key (PEM): │
│ ┌─────────────────────────────────────────────────────────────┐│
│ │ -----BEGIN RSA PRIVATE KEY----- ││
│ │ MIIEpAIBAAKCAQEA0Z3VS... ││
│ │ -----END RSA PRIVATE KEY----- ││
│ └─────────────────────────────────────────────────────────────┘│
│ │
│ Certificate Chain (CA Bundle): │
│ ┌─────────────────────────────────────────────────────────────┐│
│ │ Optional: Paste intermediate CA certificates ││
│ └─────────────────────────────────────────────────────────────┘│
│ │
│ [Validate Certificate] │
│ ✓ Private key matches certificate │
│ │
│ [Create Certificate] [Cancel] │
│ │
└─────────────────────────────────────────────────────────────────┘

[!TIP] Let’s Encrypt: Free, auto-renewing, trusted by browsers.

[!TIP] SANs: Add all needed domains in one certificate.

[!WARNING] Private Key: Keep private keys secure. Never share.


Field Description
Name Certificate identifier
Description Optional notes
Type Self-Signed, Let’s Encrypt, Custom
Field Description
Domain Primary domain (CN)
Alt. Domains Subject Alternative Names
Field Description
Organization Company name
Organization Unit Department
City Locality
State/Province Region
Country Country code
Field Description
Key Size 2048 or 4096 bits
Validity Period Days until expiry
Field Description
ACME Email Notification address
Challenge Type HTTP-01 or DNS-01
Auto Renew Enable auto-renewal
Renew Before Days before expiry
Field Description
Certificate (PEM) Public certificate
Private Key (PEM) Private key
Certificate Chain CA bundle
Field Description
Use for HTTPS Web traffic
Use for SIP TLS SIP encryption
Use for WebRTC WSS protocol
Set as Default Default certificate

Type Description Use Case
Self-Signed Generated locally Development, internal
Let’s Encrypt Free, auto ACME Production, public
Custom Upload your own Enterprise PKI
Status Meaning
Pending Being issued
Active Valid and in use
Expired Past validity date
Revoked Manually revoked
Error Issue/validation error
Size Security Performance
2048 Good Faster
4096 Better Slower

  1. Create Certificate
  2. Type = Self-Signed
  3. Domain = dev.local
  4. Key Size = 2048
  5. Validity = 365 days
  6. Enable all usage
  7. Create

Scenario 2: Let’s Encrypt for Production

Section titled “Scenario 2: Let’s Encrypt for Production”
  1. Create Certificate
  2. Type = Let’s Encrypt
  3. Domain = pbx.company.com
  4. Add SANs for sip and webrtc
  5. Enter ACME email
  6. Enable Auto Renew
  7. Create (waits for validation)
  1. Create Certificate
  2. Type = Custom
  3. Paste certificate PEM
  4. Paste private key PEM
  5. Paste CA bundle (if any)
  6. Validate (key match check)
  7. Configure usage
  8. Create
  1. Edit certificate
  2. Add new Alt. Domain
  3. Save
  4. (Let’s Encrypt re-validates)

[!NOTE] Let’s Encrypt: Domain must be publicly accessible.

[!NOTE] Rate Limits: Let’s Encrypt has issuance limits.

[!WARNING] Key Security: Never expose private keys.

  1. Use Let’s Encrypt: Free and trusted
  2. Auto Renew: Prevent expiry
  3. Include SANs: All needed domains
  4. Strong Keys: Use 2048+ bits
  5. Monitor Expiry: Watch warning alerts
Requirement Details
Public DNS Domain must resolve
Port 80 HTTP-01 challenge
No Firewall Allow Let’s Encrypt
Valid Email Notifications

Symptom Possible Cause Solution
Let’s Encrypt fails DNS not public Check DNS resolution
Key mismatch Wrong private key Verify key matches cert
Browser warning Self-signed Use Let’s Encrypt
Expired Renewal failed Manually renew
Terminal window
# View certificate details
openssl x509 -in cert.pem -text -noout
# Check expiry
openssl x509 -in cert.pem -enddate -noout
# Verify key matches cert
openssl x509 -noout -modulus -in cert.pem | openssl md5
openssl rsa -noout -modulus -in key.pem | openssl md5
Terminal window
# Test certificate chain
openssl s_client -connect pbx.company.com:443 -servername pbx.company.com
# Check Let's Encrypt validation
curl -I http://pbx.company.com/.well-known/acme-challenge/test

Term Definition
SSL/TLS Encryption protocols
PEM Certificate text format
SANs Subject Alternative Names
ACME Let’s Encrypt protocol
CA Certificate Authority
Fingerprint Certificate hash

Documentation last updated: January 2026