Files
XC_VM/docs/en/administration/ssl-generation.md
T
Divarion-D 76844fef11 docs: restructure, fix PSR-4 drift, and unify en/ru
Overhaul the Docsify documentation (English + Russian) so it matches the current
codebase and follows one consistent pattern.

Content accuracy (post-migration):
- Rewrite development/autoloader.md to PSR-4 / Composer (the old XC_Autoloader
  scanner, igbinary tmp/cache/autoload_map and registerDirectories are gone).
- PascalCase every source path (src/core -> src/Core, domain/Stream, cli/Commands,
  public/Controllers, Infrastructure/Redis, ...) across all docs.
- Replace the removed autoload.php references with vendor/autoload.php
  (build_system, bootstrap-contexts, error-handling, modules).
- ssl-generation: note that the installer now auto-generates a unique self-signed
  certificate before Nginx starts.

Common pattern (Clean & uniform):
- Strip emoji from headings; remove the in-page Navigation blocks (the Docsify
  sidebar already provides navigation).
- One H1 + intro per doc; uniform "Related files" / "Связанные файлы" section,
  added to the code-centric docs that lacked it.

Structure:
- Remove the empty stray docs/api/; move updates_checklist.md into builds/;
  link the previously-orphaned ucs-integration.md.
- Regroup the sidebars (split the oversized guides group into Developer Guides /
  Security & Access / Integrations; fold builds into Build & Release).

Augment:
- dev-workflow: Local Setup (make dev-tools) + Quality Checks (phpstan, cs, gates).
- build_system: Composer Dependencies section (committed prod-only vendor,
  committed lock, dev tools via composer install, no build-time vendor step).

en/ru parity:
- Apply the same structure, fixes and pattern to docs/ru/ (translated), including
  a new Russian ucs-integration.md. The en and ru file sets are now identical.
2026-06-26 15:56:15 +03:00

3.7 KiB

Generating SSL Certificate for Nginx in XC_VM

This guide explains how to create a self-signed SSL certificate to enable secure HTTPS connections for the built-in Nginx server in the XC_VM project.

Note: A fresh install already generates a unique self-signed certificate automatically (the installer runs openssl and writes server.key/server.crt into bin/nginx/conf/ before Nginx starts), and CertbotCronJob later replaces it with a real Let's Encrypt certificate. Follow this guide only to regenerate or replace the certificate manually.


Overview

SSL (Secure Sockets Layer) encrypts the connection between client and server, ensuring data confidentiality and user trust.
This tutorial shows how to create a self-signed SSL certificate for the embedded Nginx server in the XC_VM project.


Configuration Location

All SSL-related files (key, certificate, and config) are stored in:

/home/xc_vm/bin/nginx/conf

Navigate to this directory before proceeding:

cd /home/xc_vm/bin/nginx/conf

Step 1. Generate Private Key

Generate a 2048-bit RSA private key:

openssl genrsa -out server.key 2048

After execution, the file server.key will appear — this is your private key.
Keep it strictly confidential — it is used to sign the SSL certificate.


Step 2. Create server.cnf Configuration File

Create a configuration file containing certificate parameters:

cat > server.cnf << EOF
[req]
distinguished_name = req_distinguished_name
x509_extensions = v3_req
prompt = no

[req_distinguished_name]
C = RU
ST = Moscow
L = Moscow
O = XC_VM
OU = XC_VM
CN = XC_VM

[v3_req]
keyUsage = keyEncipherment, dataEncipherment
extendedKeyUsage = serverAuth
subjectAltName = @alt_names

[alt_names]
DNS.1 = XC_VM
EOF

Parameter explanation:

Field Value Purpose
C RU Country
ST Moscow State/Province
L Moscow City/Locality
O XC_VM Organization
OU XC_VM Organizational Unit
CN XC_VM Common Name (primary hostname)
DNS.1 XC_VM Subject Alternative Name (SAN)

Tip: For real domain names, replace DNS.1 = XC_VM with your actual domain (e.g., DNS.1 = panel.example.com) to avoid browser warnings.


Step 3. Generate Self-Signed SSL Certificate

Generate the certificate using the private key and configuration file:

openssl req -new -x509 -key server.key -out server.crt -days 3650 -config server.cnf

Explanation:

  • -new -x509 — creates a new self-signed certificate
  • -days 3650 — certificate validity period (10 years)
  • -config server.cnf — uses the custom configuration
  • Result: server.crt file containing the public certificate

Final Files

After completing all steps, the following files should be present in /home/xc_vm/bin/nginx/conf:

File Purpose
server.key Private key
server.crt Self-signed SSL certificate
server.cnf Certificate configuration file

Result

Your XC_VM Nginx server is now accessible via HTTPS using the newly created self-signed certificate.
Browsers will display a “not trusted” warning — this is expected behavior for self-signed certificates.


Notes

  • Self-signed certificates are suitable for internal use or testing only.
  • For public-facing domains, use certificates from trusted CAs (e.g., Let's Encrypt).
  • If you change the Domain/hostname (CN or DNS.1), you must regenerate the certificate.
  • To inspect the generated certificate:
openssl x509 -in server.crt -text -noout