Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

Replace the HTTPS certificate
Docs for
Overview
Getting started
What is Bitfocus Buttons?
Install Buttons and get started
Manage your Buttons license
Activate Buttons offline
Find your way around Buttons
Create your first backup
Add an ATEM connection
Choose a control method
Choose an installation path
Install Buttons on Debian or Ubuntu
Understand HA clustering
Kubernetes HA
Update or remove Buttons
Positions
Understand positions
Create a position
Add controls and sections to a position
Create your first button
Use a connection's presets
Build more capable button actions
Add more feedback to a button
Organize controls in a section
Shift Section
Organize controls with a Folder Section
Add a Popover Section
Build and reuse a Shared Section
Build a Router Section
Understand Custom Routers
Custom Router panel
Surfaces
Surface compatibility
Add and attach a surface
Device orientation
Connections
Update a connection's module safely
Monitor and troubleshoot a connection
Router integrations
VideoHub and AJA KUMO
Utah Scientific BPS
Generic SW-P-08
Nevion VideoIPath
Arkona BLADE//runner
Routing
Physical routing
Configure ports and labels
Take a physical route
Understand route status
Topology graph
Routing Presets
Get started with virtual routing
Configure Nested Shapes
Reverse routing
Tielines
Routing Projects
Routing settings
Troubleshoot a route
Tally
Understand the Tally system
Send ATEM tally and labels to a UMD
Interpret Active Tally state
TSL/UMD connections
Diagnose tally problems
NMOS
Understand NMOS in Buttons
Connect Buttons to an NMOS Registry
Built-in Registry Server
Configure NMOS connections
Discover and adopt
Browse the NMOS inventory
Manage NMOS multicast addresses
Diagnose NMOS problems
Understand Cuelists
Build a Cuelist
Read and advance a running Cuelist
Control a Cuelist from a Position
Workflows
Understand workflows
Build your first workflow
Reuse a group of workflow nodes safely
Troubleshoot a workflow
Recipes
Sequence a timed automation
Call an HTTP endpoint from a workflow
REST endpoint
Use variables
Understand variable scope
Understand nested variables
Update expressions for v1.8
Plan and use Tags
Access
Create and manage users
Create roles and assign permissions
Grant access to specific resources
Show different controls by role
Sessions
Set up PIN and NFC sign-in
SSO
Get started with SSO
Connect a generic OIDC provider
Connect LDAP or Active Directory
Map identity claims to roles
Secure a Buttons deployment
Integrations
External control
Connect to Bitfocus Listener
USB Relay
Install USB Relay on Windows
Install USB Relay on macOS
Install USB Relay on Linux
Install USB Relay on a Raspberry Pi
Get started with the Control API
Secure and monitor the Control API
Control API reference
API reference
Administration
Enable and manage installable features
Services and health
Configure and monitor scheduled backups
Restore a backup and verify it
Export or import Buttons configuration
Store and rotate connection secrets
Replace the HTTPS certificate
HA backup and recovery
Settings
Collect support information
Reference
Glossary
Button Inspector reference
Network ports reference
Expressions
Internal actions reference
Routing Presets panel reference
Startup configuration reference
Workflow nodes
Connection workflow nodes
Workflow workflow nodes
Internal workflow nodes
Position workflow nodes
API workflow nodes
Utility workflow nodes

Loading...

Previous
← Store and rotate connection secrets
Next
HA backup and recovery →
Contact support →
You are viewing documentation for Buttons 1.8.See the docs for Buttons 1.6
Buttons/Administration/Replace the HTTPS certificate

Replace the HTTPS certificate

Buttons generates its own self-signed certificate automatically so HTTPS works out of the box, without waiting on anything external. Replacing it with a certificate from a trusted authority can help you remove the browser warning users see on a self-signed certificate, and match whatever certificate practice your organization already uses.

Before you begin#

  • Access to Settings → Certificates.
  • A server certificate and matching private key, both RSA: no other key type is currently supported.
  • If your certificate has a chain, the intermediate certificates to include.
  • Awareness that saving a new certificate restarts the web service, briefly interrupting HTTPS access.

Understand what's installed today#

Settings → Certificates shows the currently installed certificate's Common Name and the date it was uploaded, not its full subject, SAN list, or expiry. If the CN doesn't match the hostname you expect, or you're not sure when it was issued, that's the extent of what's shown here; check the certificate file itself for full details if you need them.
Buttons doesn't currently warn you as a certificate approaches expiry: track renewal dates yourself, the same way you would for any other certificate you manage outside Buttons.

Plan the certificate's hostname coverage#

Buttons' own automatically generated certificate covers the single hostname it detects at generation time. When you bring your own certificate, make sure its Common Name, and any Subject Alternative Names it needs, actually covers every hostname or address people will use to reach this Buttons instance. Buttons doesn't check this for you: it accepts a certificate whose CN doesn't match how you're actually reaching the server, so a working upload doesn't by itself confirm your hostname planning was correct.

Upload a certificate#

  1. Open Settings → Certificates.
  2. Select Upload certificate files.
  3. Provide the Server certificate file, then the Private key file. The private key field stays disabled until a certificate is selected.
  4. If your certificate has a chain, include the intermediate certificates in the same upload as instructed in the dialog.
  5. Select Save and restart.
Buttons checks that the private key you provided actually matches the certificate's public key before saving, and rejects a non-RSA key outright. It does not check the certificate's chain of trust, its expiry, or whether its CN or SAN entries match this server's actual hostname: confirm those yourself before uploading.
Saving restarts the web service to apply the new certificate. Plan the change for a moment when a brief HTTPS interruption is acceptable.

Handle the private key securely#

An uploaded private key is stored directly, not through Buttons' separate Secrets encryption feature used for connection credentials. Treat the certificate files themselves with the same care you'd give any private key outside Buttons: transfer them securely, and don't leave copies lying around after the upload.

Roll back to a self-signed certificate#

There's no undo for a certificate change: replacing one certificate with another removes the previous one entirely. To return to an automatically generated certificate:
  1. Open Settings → Certificates.
  2. Select Generate self-signed certificate → Generate.
  3. Confirm: this also restarts the web service.
If you need to restore the exact certificate you replaced, you'll need your own saved copy of it; Buttons doesn't retain a history of previous certificates.

Certificates in a Kubernetes deployment#

When Buttons runs under Kubernetes, certificate management can be handed to the cluster instead, for example, through cert-manager. In that case, the page shows Certificate managed by Kubernetes, and manual upload, generation, and deletion are all unavailable from here; manage the certificate through your cluster's own tooling instead.

If you get stuck#

What you see
What to try
The upload is rejected with a key/certificate mismatch.
Confirm you're uploading the private key that was actually generated alongside this certificate, not a key from a different certificate.
The upload is rejected outright.
Confirm the private key is RSA: no other key type is currently accepted.
Users still see a certificate warning after uploading.
Confirm the certificate's CN and SAN entries actually cover the hostname or address being used to reach Buttons, and that any required intermediate certificates were included.
You need to know when the current certificate expires.
Buttons doesn't display this: check the certificate file itself, or your certificate authority's own records.
The page shows Certificate managed by Kubernetes and won't let you make changes.
Manage the certificate through your cluster's own certificate tooling instead of this page.

Where to go next#

  • Secure a Buttons deployment, for TLS as part of a broader security baseline.
  • Deploy Buttons with Kubernetes high availability, for how certificate management works in a clustered deployment.

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful