A site can hold more than one SSL certificate, but only one serves traffic at a time. That certificate has the Active badge in the certificate list. The others stay installed next to it, each with its own files on the server, and you switch between them with Activate. This lets you prepare a replacement before you take the old certificate out, without downtime.
Where to find it
Open the site and click SSL in the sidebar. You add certificates in the New certificate card. The list below it shows every certificate with its type, its domains, the path of the certificate file and the number of days until it expires.
Adding another certificate
You add it the same way as the first one, as a Let's Encrypt or ZeroSSL certificate, or as an existing certificate you paste in. When the site already has an active certificate, Ploi installs the new one and leaves the site on the current certificate. The log then says the certificate was installed but not activated. When the site has no active certificate, the new one becomes active right away.
You can request a Let's Encrypt or ZeroSSL certificate for exactly the same domains as an existing one. Every certificate gets its own files, so they never overwrite each other.
Switching to another certificate
Click Activate next to the certificate you want to use. Ploi first checks that its certificate and key files are on the server, and stops without touching anything if they are missing. It then points the site's NGINX configuration at the new files, writes the HTTP to HTTPS and www redirects again and reloads NGINX. The switch takes a few seconds. A reload lets NGINX finish open connections, so visitors don't notice it.
The button only shows for certificates that have finished installing. Signing requests and certificates requested through a load balancer can't be activated.
When this is useful
Replacing an uploaded certificate before it expires. Paste the new one with Install existing certificate, activate it, then delete the old one.
Moving from a custom certificate to Let's Encrypt. Request the Let's Encrypt certificate, wait until it has installed, then activate it.
Covering new domain aliases. Request a new certificate, use Add aliases to put the aliases in the domain field, activate it and delete the old certificate.
Changing how the certificate is validated. Request the same domains again through a DNS provider instead of HTTP validation, or with ZeroSSL instead of Let's Encrypt, and activate the new one.
Renewal
Let's Encrypt certificates renew automatically, whether they are active or not. Every server runs certbot renew once a day between 01:00 and 07:00. Certbot renews each certificate that expires within 30 days and Ploi reloads NGINX afterwards. Delete the certificates you no longer use, otherwise they keep renewing.
Certificates you pasted in yourself don't renew. Ploi checks their expiry date every day and shows it in the list, so replace them in time with the steps above.
HTTP/3
HTTP/3 belongs to the certificate, not to the site. You switch it on with Use HTTP/3 when you request a Let's Encrypt or ZeroSSL certificate, and you can't change it later. Activating a certificate without HTTP/3 turns HTTP/3 off for the site, so tick Use HTTP/3 on the replacement if you want to keep it. Pasted certificates can't use HTTP/3. More about the requirements is in Setting up HTTP/3 with NGINX on Ubuntu.
Deleting a certificate
You can delete any certificate that isn't active. Ploi revokes a Let's Encrypt certificate before it removes it. To delete the active certificate while the site has others, activate one of the others first. When you delete the last certificate of a site, Ploi removes the HTTPS configuration and the site serves plain HTTP again.
Tenants
Tenants work the same way. Every tenant has its own certificates with one of them active. Open Tenants in the site sidebar and expand Certificates on the tenant to activate or delete one. Ploi doesn't start a new request for a tenant while another request for that tenant is still running.
You can also switch certificates through the API with the activate certificate endpoint.