Configure this under Admin → Network & TLS as the appliance owner. The
appliance ships with a self-signed certificate so the UI is reachable
immediately; replace it before inviting users.
What a trusted padlock requires
A browser shows a green padlock (no warning) only when all three are true:- The appliance is reached by a hostname (FQDN) — not a bare IP. Public CAs do not issue certificates for private IP addresses.
- The certificate’s SAN matches that hostname.
- The client trusts the issuer — a public CA (trusted everywhere), or an internal CA whose root your organisation has distributed to client trust stores.
Step 1 — Set the hostname/FQDN
Under Admin → Network & TLS → Hostname / FQDN, enter the DNS name that resolves to the appliance (for exampleenclave.company.com) and save. This
becomes the canonical address used in generated links (invitations, resets), and
the services restart briefly to apply it.
Step 2 — Install a certificate
You have two options, both under Admin → Network & TLS → Web TLS Certificate.- Option A — Upload a CA-signed certificate (recommended)
- Option B — Generate a self-signed certificate
Obtain a certificate for your FQDN from a public CA (DigiCert, Let’s Encrypt,
your enterprise ACME, …) and paste the PEM blocks:
- Server certificate (leaf) — the certificate issued for your hostname.
- CA / intermediate chain — the issuing intermediate(s); required so browsers can build the chain. (Optional if already appended to the leaf.)
- Private key — the matching key (PKCS#8, PKCS#1 or SEC1 PEM).
The private key is written to the appliance and is never stored in the
database, returned by any API, or logged.
Verifying
After installing, reloadhttps://<your-fqdn>. The current certificate panel
shows the subject, issuer, SANs and expiry, with a CA-signed or
self-signed badge. A CA-signed cert whose SANs include your FQDN should show
the padlock with no warning.