> ## Documentation Index
> Fetch the complete documentation index at: https://vlyai-1c28d863.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# SSL certificates

> How vly provisions and renews SSL via Let's Encrypt. Custom certificates for enterprise customers.

vly uses [Let's Encrypt](https://letsencrypt.org) for SSL — automatic provisioning, automatic renewal, no manual cert management.

## Automatic provisioning

When DNS for a custom domain resolves correctly to vly, an SSL request fires automatically. Typical timing:

* DNS propagation: 1–60 minutes
* SSL issuance: \~10 seconds after DNS is verified
* SSL renewal: 30 days before expiry, automatic

The status flow in vly's domain settings:

```
Pending DNS → Pending SSL → Active
```

## Custom certificates

For Enterprise customers using a corporate CA or extended-validation cert:

<Steps>
  <Step title="Settings → Domains → [domain] → Certificate → Use custom">
    Toggle to custom mode.
  </Step>

  <Step title="Paste the full cert chain">
    Including intermediate certs. Format: PEM.
  </Step>

  <Step title="Paste the private key">
    Format: PEM.
  </Step>

  <Step title="Set a renewal reminder">
    vly doesn't auto-renew custom certs. Calendar a reminder 30 days before expiry.
  </Step>
</Steps>

## TLS versions

vly serves TLS 1.2+ by default; TLS 1.3 preferred. TLS 1.0 / 1.1 are disabled (deprecated by all major browsers).

## HSTS

Strict-Transport-Security is sent by default with `max-age=31536000` (1 year). To preload, request inclusion via [hstspreload.org](https://hstspreload.org) after confirming HTTPS works.

## Troubleshooting

<AccordionGroup>
  <Accordion title="'Pending SSL' for >30 minutes" icon="alert-triangle">
    Let's Encrypt rate-limited. Wait 1 hour, then click "Retry SSL".
  </Accordion>

  <Accordion title="Browser warning 'NET::ERR_CERT_AUTHORITY_INVALID'" icon="alert-triangle">
    Cert not yet provisioned, or your browser cached an old cert. Try incognito.
  </Accordion>

  <Accordion title="'Mixed content' warning" icon="alert-triangle">
    Some asset on the page is `http://`. Search code; switch to `https://` or protocol-relative `//`.
  </Accordion>
</AccordionGroup>

## Related

<CardGroup cols={3}>
  <Card title="Custom domains" icon="link" href="/deployment/custom-domains">
    Domain setup.
  </Card>

  <Card title="DNS setup" icon="globe" href="/deployment/dns-setup">
    DNS provider guides.
  </Card>

  <Card title="Security overview" icon="shield" href="/security/overview">
    Broader security model.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.