tls internal option? #91
|
Hi, I use caddy solely to proxy my docker services within my local network. Hence the most common directive I need is tls internal. I am unable to find it within the GUI. Currently I have added all my hosts using caddyfile paste method. |
Replies: 2 comments 1 reply
|
Short answer: yes, and it likely already works for your pasted hosts. There isn't a dedicated tls internal toggle in the proxy-host form yet — the TLS options there are Auto (Let's Encrypt/ZeroSSL) or a custom certificate you upload. That's the gap you hit. However, when you paste a Caddyfile containing For a purely local-network setup like yours, a first-class "Internal (Caddy local CA)" choice in the TLS dropdown makes sense, and I'm adding it. In the meantime the paste method is a fully working path. One note: internal-CA certs aren't publicly trusted, so clients need Caddy's root CA installed (or you accept the browser warning) — expected behavior for |
|
Update: this shipped in v2.46.0 🎉 Your proxy hosts now have an Internal CA (self-signed) checkbox in the TLS section (leave the certificate on Auto and tick it). CaddyUI then issues that host's certificate from Caddy's built-in internal CA — the equivalent of
Thanks for the suggestion — it made CaddyUI better for local-network setups. Feel free to reopen/comment if anything's off. |
Update: this shipped in v2.46.0 🎉
Your proxy hosts now have an Internal CA (self-signed) checkbox in the TLS section (leave the certificate on Auto and tick it). CaddyUI then issues that host's certificate from Caddy's built-in internal CA — the equivalent of
tls internal— and skips ACME/DNS-01 for it. Theinternalissuer is a core Caddy module, so no special build is needed; your clients just need to trust Caddy's root CA (pki/authorities/local/root.crtunder Caddy's data dir).docker pull applegater/caddyui:stable(or:v2.46.0)tls internal)" section…