Expiring within 7 days
| Common Name | SANs | Serial | Expires |
|---|
Recent activity
Certificates
+ +| Domain | Requests | Unique IPs | Last Requested | Latest Cert | Cached |
|---|
Requests
| Time | Client IP | Status | Duration | Serial | Validity | Reason |
|---|
Failed Requests
+ +| Time | Common Name | SANs | Client IP | Duration | Reason |
|---|
Revoked
| Common Name | SANs | Serial | Client IP | Issued At | Expires | Status |
|---|
Cache
Cached certificates
Certificates served from cache without contacting the upstream CA.| Common Name | SANs | Serial | Expires At |
|---|
Requests
+ +| Time | IP | Kind | Detail |
|---|
ACL
+ +No ACL file configured. Add an "acl" block with a "file" path to ca.json.
+Settings
+Editing — a backup is written to ca.json.bak-settings on every save; comments in ca.json are replaced by the generated file.
+ ++ + All changes apply immediately on save — no restart needed. Values are also persisted to ca.json so they survive restarts. +
+ +Upstream CA
Directory and account credentialsChanging the CA URL, email, or EAB keys re-registers the ACME account on the next request.
+Challenges
How domain control is provenDNS provider plugin used for TXT records.
+Comma-separated resolvers for DNS-01 lookups.
+Credentials passed to the provider plugin, e.g. CF_API_TOKEN.
+Empty binds all interfaces. Applied on the next challenge; the idle listener rebinds automatically.
+Applied on the next challenge; the idle listener rebinds automatically.
+Empty binds all interfaces. Applied on the next challenge; the idle listener rebinds automatically.
+Applied on the next challenge; the idle listener rebinds automatically.
+Upstream ACME operations allowed in parallel. Takes effect immediately.
+Timeouts & cache
Upstream limits and certificate cacheHow long to keep polling the CA for the new certificate after a challenge succeeds.
+Overall limit for a single upstream ACME operation.
+Re-issue instead of serving cache when fewer than this many days of validity remain.
+Always re-issue once a cached certificate is older than this.
+Dashboard
This admin consoleApplies immediately — the next login uses the new credentials.
+Dashboard TLS sessions older than this are renegotiated.
+The dashboard listener rebinds automatically on save.
+Empty binds all interfaces. The dashboard listener rebinds automatically on save.
+ACL
Access allow-listHot-reloaded — changing it switches the active allow-list immediately.
+