---
title: "SSL Certificates"
slug: "ssl-certificates"
source: "https://app.cloudpe.com/help/ssl-certificates"
updated: "2026-09-28T11:56:10.241Z"
---

# SSL Certificates

## Overview

CloudPe TLS/SSL certificate management allows you to issue, upload, validate, and deploy SSL/TLS certificates across your cloud infrastructure. You can request free automated certificates via Let's Encrypt with automatic DNS-01 challenge validation and automated renewal rotation, or upload existing custom certificates and private keys.

Certificates are organization-scoped and can be deployed directly to OpenStack Octavia load balancer HTTPS listeners and Kubernetes PaaS application ingresses with automated synchronization when certificates renew.

## Before you start

- Viewing certificates and their statuses requires the `certificates:read` permission.
- Requesting automated certificates or uploading custom certificates requires the `certificates:create` permission.
- Triggering validation verification on pending challenges requires the `certificates:update` permission.
- Deploying certificates to infrastructure resources requires the `certificates:deploy` permission, as well as `load_balancers:update` on the project hosting the load balancer.
- Deleting or revoking certificates requires the `certificates:delete` permission.
- For zero-touch automated domain validation, host your domain in CloudPe DNS under the same organization. See [DNS zones and records](/help/dns-zones-records).
- Deploying a certificate to a load balancer requires an existing listener configured with the `TERMINATED_HTTPS` protocol. See [Load balancers](/help/load-balancer-setup).

## Steps

### Request an automated Let's Encrypt certificate

1. In the sidebar, open **SSL Certificates** under **NETWORK**.

![](/kb/networking/ssl-certificates-01-list.png)

2. Select **New Certificate** (or **Issue Certificate** if no certificates exist).
3. On the **Issue / Upload Certificate** page, select the **Automated Let's Encrypt (Free)** tab.
4. Enter a friendly name for identification.
5. Provide the primary domain name (such as `app.example.com` or a wildcard domain like `*.example.com`).
6. Optionally, add additional Subject Alternative Names (SANs) one per line.
7. Select **Request Certificate**.

![](/kb/networking/ssl-certificates-02-new.png)

### Complete Domain Control Validation (DCV)

1. Navigate to the certificate detail page.
2. In the **Domain Control Validation (DCV) Required** section, inspect the challenge domain, host record, and TXT value.
3. If the domain is hosted in CloudPe DNS, the validation record is injected automatically into your zone.
4. If the domain is hosted on an external DNS provider, create the specified DNS TXT record at your DNS provider.
5. After DNS records propagate, select **Verify DCV Now** to validate domain ownership and issue the certificate.

### Upload a custom certificate (BYOC)

1. In the sidebar, open **SSL Certificates** under **NETWORK**.
2. Select **New Certificate**.
3. Select the **Upload Custom Certificate (BYOC)** tab.
4. Enter a name for the certificate.
5. Paste the certificate in PEM format into the certificate field.
6. Paste the corresponding unencrypted private key into the private key field.
7. Optionally, paste intermediate and root certificates into the CA chain field.
8. Select **Save & Validate Certificate**.

### Manage certificates and view infrastructure bindings

1. On the **TLS / SSL Certificates** list, use the filter tabs (**All Certificates**, **Free (Let's Encrypt)**, **Paid**, **Uploaded**) to filter by source.
2. Select a certificate name or select **Manage** to open the certificate detail view.
3. Review certificate parameters under **Issuer & Type**, **Validity Period**, **Serial & Fingerprint**, and **Active Infrastructure Bindings**.
4. To remove a certificate, select **Delete**.

## API

Manage certificates and bindings programmatically using the certificates endpoints.

| Method and path | Permission |
|---|---|
| `GET /api/v1/certificates` | `certificates:read` |
| `POST /api/v1/certificates/acme` | `certificates:create` |
| `POST /api/v1/certificates/upload` | `certificates:create` |
| `GET /api/v1/certificates/{certificate_id}` | `certificates:read` |
| `POST /api/v1/certificates/{certificate_id}/verify-dcv` | `certificates:update` |
| `POST /api/v1/certificates/{certificate_id}/bindings` | `certificates:deploy` |
| `DELETE /api/v1/certificates/{certificate_id}/bindings/{binding_id}` | `certificates:deploy` |
| `DELETE /api/v1/certificates/{certificate_id}` | `certificates:delete` |

List all certificates in your organization:

```bash
curl https://app.cloudpe.com/api/v1/certificates \
  -H "Authorization: Bearer <API_KEY>"
```

Request an automated Let's Encrypt certificate:

```bash
curl -X POST https://app.cloudpe.com/api/v1/certificates/acme \
  -H "Authorization: Bearer <API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
        "name": "Production Web App",
        "primary_domain": "app.example.com"
      }'
```

Upload a custom certificate bundle:

```bash
curl -X POST https://app.cloudpe.com/api/v1/certificates/upload \
  -H "Authorization: Bearer <API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
        "name": "Custom Wildcard",
        "certificate_pem": "-----BEGIN CERTIFICATE-----\n...\n-----END CERTIFICATE-----",
        "private_key_pem": "-----BEGIN RSA PRIVATE KEY-----\n...\n-----END RSA PRIVATE KEY-----"
      }'
```

Trigger immediate DCV validation for a pending certificate:

```bash
curl -X POST https://app.cloudpe.com/api/v1/certificates/<certificate_id>/verify-dcv \
  -H "Authorization: Bearer <API_KEY>"
```

Deploy a certificate to an active load balancer listener:

```bash
curl -X POST https://app.cloudpe.com/api/v1/certificates/<certificate_id>/bindings \
  -H "Authorization: Bearer <API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
        "target_type": "LOAD_BALANCER_LISTENER",
        "target_id": "<listener_id>"
      }'
```

Delete a certificate:

```bash
curl -X DELETE https://app.cloudpe.com/api/v1/certificates/<certificate_id> \
  -H "Authorization: Bearer <API_KEY>"
```

## Limits & billing

- Automated Let's Encrypt certificates are issued at no additional cost.
- Automated certificates include automatic renewal and zero-touch validation for domains hosted on CloudPe DNS.
- Certificates are organization-scoped and can be bound across multiple projects within the same organization.
- Binding certificates to load balancer listeners requires the listener to be configured with the `TERMINATED_HTTPS` protocol.

## Troubleshooting

| Message | What it means | What to do |
|---|---|---|
| `Load balancer listener not found` | The target load balancer listener ID does not exist or does not belong to your organization. | Verify the listener UUID in the Load Balancers dashboard or call `GET /api/v1/load-balancers/{lb_id}/listeners`. |
| `Private key not available for binding deployment` | The certificate's private key could not be retrieved from secure storage to configure TLS termination. | Ensure the certificate was created with a private key, or re-upload the certificate and private key bundle. |
| `Certificate not found` | The requested certificate UUID does not exist or has been deleted. | Check the certificate UUID in the certificates list or call `GET /api/v1/certificates`. |
| `Binding not found` | The specified infrastructure binding UUID does not exist or was already removed. | Verify active bindings on the certificate detail page or query `GET /api/v1/certificates/{certificate_id}`. |
| `PaaS app not found` | The target PaaS application ID does not exist or does not belong to your organization. | Verify the application UUID in your project before creating the certificate binding. |

## FAQ

**How does automatic certificate renewal work?**
Automated Let's Encrypt certificates have automatic renewal enabled by default. Prior to expiration, CloudPe initiates validation challenges and renews the certificate. Active infrastructure bindings on load balancers and PaaS applications are updated automatically.

**Can I attach a certificate to multiple load balancers?**
Yes. Because certificates are scoped to your organization, you can create multiple bindings to deploy the same certificate across different load balancer listeners and PaaS apps.

**What domain validation method is used for automated certificates?**
Automated certificates use DNS-01 validation. If your DNS zone is hosted on CloudPe DNS, challenge TXT records are created automatically. For external DNS providers, you can manually create the required TXT record.

**Can I bind a certificate to an HTTP listener?**
No. Load balancer listeners require the `TERMINATED_HTTPS` protocol for TLS termination. To use SSL on a load balancer, configure a `TERMINATED_HTTPS` listener.

## Related

- [Load balancers](/help/load-balancer-setup)
- [DNS zones and records](/help/dns-zones-records)
- [VPC networks, subnets and routers](/help/vpc-networks-subnets)