Replacing Self-Signed Certificates¶
During installation, the system creates self-signed certificates that are used when connecting to the Web UI. Administrators may wish to replace these with valid, trusted certificates for the domain Kasm is to be published on. An alternative is to place Kasm Server behind a self-managed reverse proxy such as Nginx or Caddy. See the Reverse Proxy documentation for more details on this configuration.
Acquiring valid certificates is outside the scope of this document, but once acquired, the following steps may be used to replace Kasm’s self signed certificates. The certificate and key must be in PEM format.
For multi-server installations, repeat the following steps on each Web App role.
Stop the Kasm Services
sudo cp <your_cert> /opt/kasm/current/certs/kasm_nginx.crt sudo cp <your_key> /opt/kasm/current/certs/kasm_nginx.key
Start the Kasm Services