Skip to content
Klacos
SSL/TLS certificates

Automatic SSL certificates: every domain encrypted, no expiry date to watch

A certificate expires on a Friday evening, and your site turns into a warning nobody clicks past. With Klacos, every domain you add gets its certificate, renewed well before it expires, with no restart. Prefer your own certificates? They take priority.

Illustration: a workstation protected by a padlock.
The problem

An expired certificate is a site nobody sees

When a certificate expires, browsers show a warning instead of your site, and most visitors leave. With dozens of domains, sooner or later an expiry date slips through.

Klacos issues a certificate for every domain you add, renews it 30 days before expiry and applies it on the fly without dropping a connection. If a renewal fails, the console flags it straight away, then again 30 and 7 days before expiry, long before your visitors see an error. A certificate you’ve bought can be imported and takes priority, with the same alerts.

The keys for automatically issued certificates stay on the machine that serves your site: the console only receives their details, such as the domain and the expiry date.

Site page in the console: site status, domains and certificate, origin and routing rules, pages and headers.
Klacos console (French interface), demo data.
What you get

Encryption for your domains, with nothing to keep an eye on

Issued for you

Add a domain and the certificate follows, from an authority every browser trusts.

Renewed early

30 days before expiry, applied with no restart and no interruption.

Your own certificates

Import yours: they take precedence over the ones issued automatically.

All your domains

Every domain and subdomain has its own certificate, picked for each connection.

HTTPS everywhere

Visits over http are redirected to https, with path and parameters kept.

Timely alerts

The console warns you 30 and then 7 days before expiry, and whenever a renewal fails.

Current TLS

TLS 1.2 and 1.3 for every connection your visitors make.

Security headers

The usual set offered in one click, site by site, never forced on you.
Security headers

The right headers, without breaking your site

Security headers tell the browser to always use https, not to guess a file’s type, not to pass the full address of your pages on to other sites, and not to let your site be shown inside someone else’s frame. The usual set is added in one click, site by site.

It’s never forced on you, because a header that’s too strict can break an integration or a tool you rely on. You switch it on when you’re ready, and off again the same way. To close part of the site rather than encrypt it, see access rules. Certificates are part of your site’s protection, and the same service keeps your pages fast and online.

Illustration: blocks and modules stacked on a base.
Questions

Questions about SSL certificates

What do I need to do to get a certificate?

Point your domain at Klacos, and prove once in the console that it’s yours, with a DNS record. The certificate follows with nothing else to do.

Can I keep the certificate I bought?

Yes. Once imported it takes priority, and the console warns you before it expires, as it does for the others.

Are subdomains covered?

Each one gets its own certificate. If you import a wildcard certificate, it covers one level of subdomains.

Is the link to my server encrypted too?

It can be: your server can be reached over https, with its certificate checked.

Opening early 2027

Encrypt every domain without giving it a thought

Request early access, or talk to us about the domains and certificates you manage today.