Security & SSL
Configuring Let's Encrypt SSL
Enable secure HTTPS connections automatically. Learn about certificate renewal, verification, and HTTP challenges.
2 min read · Updated June 05, 2026
- Ensure your domain nameservers or root A records are pointed to your DockSpin IP and fully propagated.
- Navigate to the SSL status tab under your Site Cockpit.
- Click 'Issue SSL Certificate'. The system will launch a Let's Encrypt validation script.
- Once verification completes, HTTPS redirect will be enabled automatically.
- Renewal occurs silently in the background every 90 days.
SSL is provisioned via Let's Encrypt using ACME challenges. For SSL to succeed, the Let's Encrypt server must be able to reach your site via HTTP (port 80). If you have configured custom firewall rules blocking port 80 or have incorrect A records, the certificate authority will fail to validate and return an error. If utilizing Cloudflare proxy, configure SSL mode to 'Full' or 'Full (strict)' to avoid redirect loops.