HTTPS Configuration
Caddy is the first web server to enable HTTPS by default. It automatically obtains and renews certificates from Let’s Encrypt and other ACME CAs.Automatic HTTPS
HTTPS is enabled automatically for all sites with hostnames:Caddy automatically:
- Obtains certificates from Let’s Encrypt
- Renews certificates before expiration
- Staples OCSP responses
- Redirects HTTP to HTTPS
Certificate Automation
Automation Policies
Configure how certificates are obtained and managed:Key Types
Supported key types:ec256- ECDSA P-256 (default, recommended)ec384- ECDSA P-384rsa2048- RSA 2048-bitrsa4096- RSA 4096-bited25519- Ed25519
Certificate Issuers
Let’s Encrypt
Default production CA:ZeroSSL
Alternative CA with longer validity:Internal Certificates
For development or internal services:On-Demand TLS
Obtain certificates during TLS handshakes:Permission Module
Validate domains before issuing certificates:Manual Certificates
Load from Files
Load from Folder
Automatically load all certificates from a directory:DNS Challenge
Use DNS-01 challenge for wildcard certificates or when HTTP-01 is unavailable:TLS Settings
Connection Policy
Configure TLS settings per hostname:Client Authentication
Require client certificates (mutual TLS):Certificate Storage
File System (Default)
Certificates are stored in:- Linux:
$XDG_DATA_HOME/caddyor$HOME/.local/share/caddy - macOS:
$HOME/Library/Application Support/Caddy - Windows:
%APPDATA%\Caddy