# SSL certificate management

**URL:** <https://discourse.haproxy.org/t/ssl-certificate-management/3419>\
**Category:** Help!\
**Created:** [January 20, 2019, 5:12am UTC](https://discourse.haproxy.org/t/ssl-certificate-management/3419 "2019-01-20T05:12:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pattie](https://avatars.discourse-cdn.com/v4/letter/p/47e85d/32.png) [@pattie](https://discourse.haproxy.org/u/pattie)\
**Post date:** [January 20, 2019, 5:12am UTC](https://discourse.haproxy.org/t/ssl-certificate-management/3419/1 "2019-01-20T05:12:38Z")

</div>

I want to use haproxy as SSL termination for a content management system, but it’d need to be dynamic since users can add new domains and upload their site’s certs by themselves through their site management. I could do a script in python or bash that would do that, copy the certs to the haproxy host and trigger a seamless reload, but I was wondering if something already exists. Thanks.

---

<div class="post-metadata">

**Author:** ![ciprian.craciun](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/ciprian.craciun/32/722_2.png) [@ciprian.craciun](https://discourse.haproxy.org/u/ciprian.craciun)\
**Post date:** [January 21, 2019, 7:34am UTC](https://discourse.haproxy.org/t/ssl-certificate-management/3419/2 "2019-01-21T07:34:00Z")

</div>

I can’t directly answer your question, but the following article (from the HAProxy enterprise site) might help. (The patch seems to be available in HAProxy open source `v1.8`.)

> **[Truly Seamless Reloads with HAProxy - No More Hacks! - HAProxy Technologies](https://www.haproxy.com/blog/truly-seamless-reloads-with-haproxy-no-more-hacks/)**
>
> HAProxy Technologies' R&D has released a patchset to enable seamless reloads of HAProxy without dropping packets in the process.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [January 21, 2019, 8:11am UTC](https://discourse.haproxy.org/t/ssl-certificate-management/3419/3 "2019-01-21T08:11:18Z")

</div>

Seamless reloads are supported in haproxy starting with the 1.8 release, not need to patching anything.

Installing new certificates currently does require reloading haproxy and there is no workaround for that at this time.

I know there is some interest in adding/removing certificates from the admin socket, not requiring an actual reload (iirc this was discussed once on the mailing list). I’m not sure if someone is working on this or not though. I will have to go through the archives.

---

<div class="post-metadata">

**Author:** ![pattie](https://avatars.discourse-cdn.com/v4/letter/p/47e85d/32.png) [@pattie](https://discourse.haproxy.org/u/pattie)\
**Post date:** [January 21, 2019, 2:30pm UTC](https://discourse.haproxy.org/t/ssl-certificate-management/3419/4 "2019-01-21T14:30:11Z")

</div>

As long as I can do a seamless reload, it’s fine. I was also wondering for the copy of the certificate itself in the cert directory, if there was a way to do that remotely with some admin command to avoid to have to implement my own solution. I’m gonna search into the mailing list, thanks!
