Skip to content
DocsGo to Dashboard
Connect a domain

Automatic SSL issuance and renewal, with live certificate inspection

Certificates are issued automatically once the traffic record resolves, so this step is mostly about watching the platform checks and knowing when issuance has actually succeeded rather than assuming it did.

1. Publish the traffic record first#

Automatic issuance depends on the Live traffic routing record, so if the SSL certificate check still reports Waiting, go back to group 3. Route traffic to enable automatic SSL and confirm the record is published at your provider. That group stays Locked until the ownership and origin checks pass.

Setup workflow on a fully onboarded domain with the platform checks group expanded: Origin reachable, SSL certificate, Delivery configuration, and Live traffic detected all report Ready
Automatic issuance completes when origin, delivery, and traffic checks are all ready.

2. Let WebOptiva issue the certificate#

The workflow shows this as step 5, Weboptiva secures delivery, with the actor chip Automatic and the next action Weboptiva is issuing SSL and preparing secure delivery automatically. Group 4, We secure and prepare the website automatically, lists the checks that must all report Ready: Origin reachable, SSL certificate, Delivery configuration, and Live traffic detected.

3. Re-check while issuance runs#

Press Check DNS records as often as you like. A renewal-safe worker also re-checks due domains on a schedule, so a renewal problem surfaces before visitors see it, and a manual re-check is always available regardless of that worker. The ACME warning stays visible until issuance succeeds — it does not disappear on a page reload.

4. Inspect the issued certificate#

Certificates are stored per domain, so the issued one can be inspected directly on the domain record, including its expiry, to confirm which hostname it covers and how long you have before renewal.

Expected result#

Step 5, Weboptiva secures delivery, reads Completed, the SSL certificate check reports Ready, and step 6 Website live becomes the current step. Until then, HTTPS is not guaranteed for the hostname. The last action is to deploy — see Activate and accelerate.

One certificate per hostname#

Certificates are issued for the hostname you added, not for the whole workspace, so each domain moves through this step on its own schedule. That is also why the ACME warning is per domain — a second domain that has not finished onboarding will keep its own warning visible, and fixing one does not clear the other.

Back to Connect a domain