Security
SSL certificates
Follow issuance, export when allowed, retry failures, or remove a certificate.
#Overview
Follow issuance, export when allowed, retry failures, or remove a certificate.
#Choose a certificate mode
Automatic mode requests and renews a certificate after zone and routing readiness. Custom mode accepts a supplied certificate and key under the displayed validations; protect the private key strictly.
Pending, active, expiring, and failed states guide action. Retry is appropriate after fixing DNS or origin issues; removing a certificate deletes configuration and can interrupt HTTPS.
#Resolve failed issuance
Confirm the domain resolves to cdn.pizza configuration.
Check CAA and challenge availability.
Correct the blocker and choose Retry.
Test the served chain, name, and expiry.
#State lifecycle
| State | Meaning |
|---|---|
pending | Issuance or deployment in progress. |
active | Certificate valid and deployed. |
expired | Certificate expired; HTTPS traffic requires remediation. |
error | Issuance or deployment failed; fix DNS/CAA and retry. |