Summary
product-guide/system/certificates/ does not document what happens to the install-time self-signed certificate as it nears expiry, or whether VergeOS regenerates it automatically.
Type
Conceptual (+ small how-to addendum on the existing Certificates page)
Gap
The page covers Let's Encrypt renewal and manual cert install, and notes the install-time self-signed cert should be kept for local/recovery access — but does not say:
- Whether the native self-signed cert auto-renews/regenerates before expiry
- Its lifetime
- Whether customers without a public CA need to take any action as expiry approaches
- What the
Renew column on the cert list means for self_signed entries (the modify form only exposes the renew flag for Let's Encrypt)
Per Larry Ludlow: "The verge self signed certs handle themselves, it will not expire." That needs to be in the public doc.
Suggested Content
Add a short subsection under the existing "Default Self-Signed Certificate" area covering:
- Lifecycle: regenerated/renewed automatically by VergeOS, no admin action required
- Behavior of the
Renew column for self-signed rows (if user-actionable)
- Guidance for air-gapped / no-CA sites that rely on the default cert long-term
Context
Raised by a partner (Top Golf, Oberhausen site) when the install-time self-signed cert showed 26 days to expiry. Confirmed via Slack with engineering that no action is required, but no public doc captures that.
Summary
product-guide/system/certificates/does not document what happens to the install-time self-signed certificate as it nears expiry, or whether VergeOS regenerates it automatically.Type
Conceptual (+ small how-to addendum on the existing Certificates page)
Gap
The page covers Let's Encrypt renewal and manual cert install, and notes the install-time self-signed cert should be kept for local/recovery access — but does not say:
Renewcolumn on the cert list means forself_signedentries (the modify form only exposes therenewflag for Let's Encrypt)Per Larry Ludlow: "The verge self signed certs handle themselves, it will not expire." That needs to be in the public doc.
Suggested Content
Add a short subsection under the existing "Default Self-Signed Certificate" area covering:
Renewcolumn for self-signed rows (if user-actionable)Context
Raised by a partner (Top Golf, Oberhausen site) when the install-time self-signed cert showed 26 days to expiry. Confirmed via Slack with engineering that no action is required, but no public doc captures that.