openstead
Networking

HTTPS and certificates

Understand automatic certificates, domain readiness, and HTTPS troubleshooting.

Suggest a change

Openstead manages HTTPS certificates for verified custom domains on web services and static sites. You do not need to upload a private key to connect a standard hostname.

Certificate activation

First publish the ownership and routing records shown in Custom domains. Openstead verifies DNS, configures the hostname's route, and checks that a valid certificate is served for that hostname.

A domain can be verified while its certificate is still pending. Wait until the dashboard reports that HTTPS is active before using the hostname for production callbacks, login links, or customer communications.

Certificates renew automatically while the domain remains correctly routed and the verification requirements continue to be met. Keep the ownership TXT record and current DNS routing.

HTTPS at the application

The public HTTPS connection terminates at Openstead's routing layer. Your application should listen on its configured internal port using the framework's normal production server settings.

Configure the framework's trusted-proxy behaviour appropriately so it generates HTTPS links and secure cookies. A mismatch between the application's expected scheme and proxy headers can cause redirect loops or incorrect callback URLs.

Do not disable certificate validation in an external client to hide a hostname or certificate error. Correct the domain setup instead.

Troubleshoot certificate issuance

SymptomWhat to inspect
DNS still pendingOwnership TXT record, destination A/CNAME, stale AAAA records, and proxying
Domain verified, HTTPS pendingAllow certificate activation time; check DNS remains direct and stable
Certificate for another hostConfirm the exact hostname was added and points to this service
Browser redirects repeatedlyApplication URL, trusted proxy settings, canonical-host redirect, and HTTPS middleware
Mixed-content warningApplication assets or API URLs hardcoded with http://

If the domain has restrictive CAA records, review whether they permit the certificate authority being used for issuance. Contact support with the domain and the dashboard's error detail before weakening an existing DNS policy indiscriminately.

Database transport is separate

Website HTTPS does not turn a private database port into a public TLS endpoint. PostgreSQL, MySQL, and Key Value use their private connection model. Do not assume a website certificate applies to a database client's connection string.

Requesting help

Include the hostname, time of the last DNS change, DNS provider, displayed domain status, and any browser error. A screenshot of DNS records can help after sensitive unrelated records are removed. Never send certificate private keys or account credentials.

Need a hand? Contact Openstead support.

On this page