Skip to main content

Install SSL certificate to XOA

VKB-1158How-to
📦 Applies to
Xen Orchestra
🗓️ Created
2025-03-05
🔄 Updated
2026-10-10

Environment​

  • The XOA main configuration file can be found in /etc/xo-server/config.toml.
  • The default location for the certificates is /etc/ssl.
  • The default self signed certificate and key are called cert.pem and key.pem.
  • If there is no certificate or the self signed certificate has expired, a new one will be created.

Procedure​

  1. Generate your certificate request with openssl directly on the server. Example:

    root@dom0
    # sudo openssl req -newkey rsa:2048 -keyout /etc/ssl/pkey.key -out /etc/ssl/csr.csr
  2. Follow the steps of the prompt.

  3. Be sure you keep the pass phrase in a safe place, you will need it.

  4. Once the CSR is generated you can provide it to your certificate provider to generate your certificate.

    • Be sure to ask for .pem certificates or you will need to convert them through openssl.
  5. Once you are provided with the cert and key file you should place them in /etc/ssl.

  6. In config.toml, change the cert and key file names to point to the new ones.

  7. Restart the web server for the new files to be taken into account:

    root@xoa
    # systemctl restart xo-server

More documentation about xo-server configuration here: https://docs.xen-orchestra.com/configuration#https-and-certificates

Verification​

After the restart, xo-server serves the web interface with the new certificate and key configured in config.toml.