# Improved SSL certificate generation

**URL:** <https://discuss.write.as/t/improved-ssl-certificate-generation/2127>\
**Category:** Announcements\
**Created:** [December 2, 2020, 10:26pm UTC](https://discuss.write.as/t/improved-ssl-certificate-generation/2127 "2020-12-02T22:26:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![matt](https://discuss.write.as/user_avatar/discuss.write.as/matt/32/2760_2.png) [@matt](https://discuss.write.as/u/matt)\
**Post date:** [December 2, 2020, 10:26pm UTC](https://discuss.write.as/t/improved-ssl-certificate-generation/2127/1 "2020-12-02T22:26:21Z")

</div>

We’ve just revamped how SSL certificates are generated on Write.as, so getting new custom domains online should be much smoother now!

Our previous process, which could involve some delay while we checked your domain, has been replaced by an on-demand process, which creates the certificate on the very first visit to your site. So, after [setting up your custom domain](https://howto.write.as/setting-up-a-custom-domain), you might notice a minor delay on your first visit as we create the certificate for the very first time. However, after that, the site will load quickly for everyone.

## Troubleshooting

There are certain issues that might come up during setup with our new infrastructure.

### `ERR_SSL_PROTOCOL_ERROR` during setup

If you see this error for your custom domain on Write.as, you simply need to set the domain in your blog’s settings.

![Screenshot from 2020-12-02 16-30-17](https://discuss.write.as/uploads/default/original/1X/c772022150c7f0c5bab9f94847e8e90c46ac35d0.png)

You can do this by going to your [Blogs](https://write.as/me/c/) page, clicking **Customize** under the blog you want to modify, and adding the domain in the **Custom domain** field. Once you’ve done that, refresh your site to automatically generate the certificate.

### CloudFlare

This new process should work for the vast majority of setups and DNS providers. However, if you use CloudFlare, you’ll need to **disable their traffic proxy feature** and use them for **DNS only**.

To do this, navigate to the **DNS** tab in CloudFlare. Next, click **Edit** next your domain, and ensure that the “Proxy Status” says **DNS only**. (If it shows an orange cloud that says “Proxied,” simply click the cloud to change the status.)

![Screenshot from 2020-12-02 17-11-14](https://discuss.write.as/uploads/default/original/1X/995c96c6121fb96f1dfd4b4e4021d0d908fab838.png)

Save these changes, and after a short bit of time your site will work correctly!

We know that some users want the additional protection offered by CloudFlare. If you do, just get in touch with us [@old-support](https://discuss.write.as/groups/old-support) so we can discuss a paid plan with CloudFlare support included.

For any users _currently_ using CloudFlare’s protection on their Write.as site, we’ve made the changes necessary to keep your site live, as part of your Pro subscription. But in the near future, we’ll get in touch to discuss changes needed on your end.

* * *

Please let us know if you notice issues with your site after today’s changes, or if you have any other questions!

---

<div class="post-metadata">

**Author:** ![jdrydn](https://discuss.write.as/user_avatar/discuss.write.as/jdrydn/32/814_2.png) [@jdrydn](https://discuss.write.as/u/jdrydn)\
**Post date:** [December 2, 2020, 10:40pm UTC](https://discuss.write.as/t/improved-ssl-certificate-generation/2127/2 "2020-12-02T22:40:59Z")

</div>

Hi there,

Are you able to share more about how you generate SSL certs for custom domains? Is it a custom solution you guys built or an off-the-shelf like KiloSSL?

Thanks,  
James

---

<div class="post-metadata">

**Author:** ![matt](https://discuss.write.as/user_avatar/discuss.write.as/matt/32/2760_2.png) [@matt](https://discuss.write.as/u/matt)\
**Post date:** [December 3, 2020, 3:19pm UTC](https://discuss.write.as/t/improved-ssl-certificate-generation/2127/3 "2020-12-03T15:19:23Z")

</div>

Sure thing! We had a custom solution in place for the past several years, and now we’ve switched to [Caddy](https://caddyserver.com/).

Our original solution periodically checked each domain we hosted, then generated a new Nginx configuration for the site plus the certificate via [Let’s Encrypt](https://letsencrypt.org/). Now we’ve replaced Nginx with Caddy as our reverse proxy server, and get all of that certificate management for free, in a more stable package.

---

<div class="post-metadata">

**Author:** ![huride](https://discuss.write.as/user_avatar/discuss.write.as/huride/32/4290_2.png) [@huride](https://discuss.write.as/u/huride)\
**Post date:** [October 25, 2024, 10:10am UTC](https://discuss.write.as/t/improved-ssl-certificate-generation/2127/4 "2024-10-25T10:10:15Z")

</div>

> [@matt](#):
>
> We know that some users want the additional protection offered by CloudFlare. If you do, just get in touch with us [@old-support](https://discuss.write.as/groups/old-support) so we can discuss a paid plan with CloudFlare support included.

@matt, cloudflare problem for me it seems. Can you please remedy? Thanks!

---

<div class="post-metadata">

**Author:** ![matt](https://discuss.write.as/user_avatar/discuss.write.as/matt/32/2760_2.png) [@matt](https://discuss.write.as/u/matt)\
**Post date:** [October 30, 2024, 5:36pm UTC](https://discuss.write.as/t/improved-ssl-certificate-generation/2127/5 "2024-10-30T17:36:22Z")

</div>

Hey @huride, are you still having issues with this? It looks like your site is up and running fine right now.

Otherwise, this information is out of date now – we don’t really support this custom setup due to the setup and maintenance cost to us. But if it’s especially important for your site, please let me know and we can work something out.

---

<div class="post-metadata">

**Author:** ![huride](https://discuss.write.as/user_avatar/discuss.write.as/huride/32/4290_2.png) [@huride](https://discuss.write.as/u/huride)\
**Post date:** [October 30, 2024, 6:47pm UTC](https://discuss.write.as/t/improved-ssl-certificate-generation/2127/6 "2024-10-30T18:47:53Z")

</div>

I disabled cloudflare proxy and it now works. If you could enable cloudflare support on my account, great and thanks. But if I need to make a choice, I find availability of attach.as is much more necessary.

EDIT: so attach.as please 😊
