Skip to content

Docs: Document self-signed certificate auto-renewal / expiration behavior #470

Description

@jasnoyaeger

Summary

product-guide/system/certificates/ does not document what happens to the install-time self-signed certificate as it nears expiry, or whether VergeOS regenerates it automatically.

Type

Conceptual (+ small how-to addendum on the existing Certificates page)

Gap

The page covers Let's Encrypt renewal and manual cert install, and notes the install-time self-signed cert should be kept for local/recovery access — but does not say:

  • Whether the native self-signed cert auto-renews/regenerates before expiry
  • Its lifetime
  • Whether customers without a public CA need to take any action as expiry approaches
  • What the Renew column on the cert list means for self_signed entries (the modify form only exposes the renew flag for Let's Encrypt)

Per Larry Ludlow: "The verge self signed certs handle themselves, it will not expire." That needs to be in the public doc.

Suggested Content

Add a short subsection under the existing "Default Self-Signed Certificate" area covering:

  • Lifecycle: regenerated/renewed automatically by VergeOS, no admin action required
  • Behavior of the Renew column for self-signed rows (if user-actionable)
  • Guidance for air-gapped / no-CA sites that rely on the default cert long-term

Context

Raised by a partner (Top Golf, Oberhausen site) when the install-time self-signed cert showed 26 days to expiry. Confirmed via Slack with engineering that no action is required, but no public doc captures that.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions