TLS certificates
NullWard terminates TLS for your services. Each service can get a certificate automatically over ACME, for example from Let's Encrypt, or use one you upload. Turn on HTTPS for a service Open the service, then go to TLS Configuration. Turn on Inbound TLS Enabled. Choose a Certificate Mode: ACME (Let's Encrypt): NullWard obtains and renews the certificate. Manual (Upload Certificate): paste the Certificate PEM (the full chain) and the Private Key PEM. The private key is encrypted before it's stored. Click Save Changes. ACME settings on the service ACME Provider: Default (Let's Encrypt), or a provider you've added under Settings > Certificates. ACME Email: the email address for the ACME account registration. Domains: leave this empty to put every hostname of the service on one certificate, or list specific names. Wildcard hostnames can only be included when the provider uses DNS-01. Renewal Node (clusters): which node renews the certificate. By default renewals are spread across nodes automatically. Force Renew: renews now, without waiting for the 30-day expiry window. Use it after you change provider settings. Certificates are checked for renewal every Renewal check interval (default 60 minutes) and renewed when about 30 days remain. ACME providers and DNS-01 Under Settings > Certificates > ACME Certificate Providers, click Add Provider to use another certificate authority or the DNS-01 challenge. Provider Type: Let's Encrypt, ZeroSSL, Google Trust Services, or a custom ACME CA. ZeroSSL and Google Trust Services need EAB credentials (key ID and HMAC key) from your account with them. Challenge Type: HTTP-01 needs port 80 reachable from the internet. DNS-01 creates a DNS record through your DNS provider's API. It supports wildcard certificates, works when port 80 is closed, and is recommended for clusters. DNS providers for DNS-01: Cloudflare, AWS Route 53, Google Cloud DNS, DigitalOcean, Azure DNS, Namecheap, GoDaddy and OVH. Auto-validate on staging before production: tries the CA's staging environment first, to avoid hitting production rate limits with a bad configuration. Each issuance and renewal attempt is listed under Security Events > ACME Events, with its status (success, failure, started or skipped), domains, provider and challenge type. Protocols and ciphers Per service, under TLS Configuration > Protocol & Ciphers: Minimum TLS Version and Maximum TLS Version: TLS 1.2 or 1.3. Cipher Suites (TLS 1.2): the ECDHE AES-GCM and ChaCha20-Poly1305 suites. HTTP/3 (QUIC): inherit the global setting, or turn it on or off for this service. See HTTP/3. HTTPS enforcement and HSTS Enforce HTTPS redirects HTTP requests to HTTPS with a 301. Enable HSTS sends Strict-Transport-Security, with options for max-age, include subdomains and preload. TLS to your backend Upstream TLS > Skip Certificate Verification controls how NullWard checks the certificate of an https:// backend: Use Global Default, Skip Verification (for self-signed backend certificates) or Require Valid Certificate. A destination can override this with its own TLS Verification setting.
NullWard documentation