Skip to content

Automatic HTTPS

Every hub gets a real, browser-trusted HTTPS certificate (the padlock icon, no security warnings) automatically. There’s nothing to buy, register, or configure to make this work.

When your hub finished setup, it was given an address like yourhub.hub.citinet.cloud. That address already has a real certificate behind it, issued the moment your hub first came online, and renewed automatically before it ever expires. You will not see a “your connection is not private” warning when you or your members visit it.

You don’t need to:

  • Own a domain name
  • Set up an account with a certificate provider
  • Touch any DNS settings
  • Do anything at all when the certificate is due for renewal

Your hub’s software checks in with a small, central Citinet service (the “cert broker”) when it needs a certificate, at first setup, and again automatically as the current one approaches expiry. That service is the only part of this that’s centralized; the certificate itself, once issued, is used entirely by your own hub. If you want the full technical detail, see The Cert Broker.

A security warning in the browser when visiting your hub’s normal address is unusual and worth reporting. See Troubleshooting & Getting Help. It should not happen under normal operation.