Skip to content

TLS Certificates

All flexFS server components communicate over TLS by default. On first startup, each server automatically generates a self-signed certificate if neither a certificate nor a key is found.

When a server starts and finds neither a certificate nor a key at its configured paths, it generates a self-signed certificate with the following properties. If only one of the two files exists, the server refuses to start and reports which file is missing.

PropertyValue
Key typeECDSA P-256
SubjectCN=flexfs, O=Paradigm4, Inc., L=Boston, ST=Massachusetts, C=US
DNS SANslocalhost
IP SANs127.0.0.1, ::1
Validity100 years (876,000 hours)
Key usageDigital Signature, Key Encipherment
Extended key usageServer Authentication
Serial number128-bit random (per RFC 5280)
File permissions0600 (owner read/write only)

Auto-generated certificates are suitable for development and internal deployments. For production deployments accessible over the internet, use custom certificates issued by a trusted CA.

To use your own TLS certificates, provide the cert and key files via command-line flags on the server:

Terminal window
meta.flexfs start --sslCert /path/to/cert.pem --sslKey /path/to/key.pem
Terminal window
proxy.flexfs start --sslCert /path/to/cert.pem --sslKey /path/to/key.pem
Terminal window
admin.flexfs start --sslCert /path/to/cert.pem --sslKey /path/to/key.pem
Terminal window
free.flexfs start --sslCert /path/to/cert.pem --sslKey /path/to/key.pem

Each server stores its auto-generated certificate and key under the flexFS home folder:

ServerDefault cert pathDefault key path
meta.flexfs~/.flexfs/ssl/cert~/.flexfs/ssl/key
proxy.flexfs~/.flexfs/ssl/cert~/.flexfs/ssl/key
admin.flexfs~/.flexfs/ssl/cert~/.flexfs/ssl/key
free.flexfs~/.flexfs/ssl/cert~/.flexfs/ssl/key

All servers share the same default certificate paths. When using --sslCert and --sslKey, the server reads from the specified paths instead.

TLS can be disabled on individual servers, for example for testing in trusted internal networks or behind a reverse proxy (e.g., nginx) or load balancer that handles TLS termination:

ComponentFlag
meta.flexfs--noSSL
proxy.flexfs--noSSL
admin.flexfs--noSSL
free.flexfs--noSSL

--noSSL affects only the server. Mount clients and the command-line tools always connect with HTTPS unless told otherwise:

  • Behind a TLS-terminating reverse proxy or load balancer, clients keep using HTTPS to the proxy, so no client changes are needed. For meta.flexfs, the proxy must also pass WebSocket connections through, because mount clients hold their session over a WebSocket. API access rules cannot tell clients apart behind a proxy, since every request arrives from the proxy’s address.
  • Clients connecting directly to a --noSSL server must be started with the matching Internal flag: --noAdminSSL for an admin or free server, --noMetaSSL for a metadata server, or --noProxySSL for a proxy server. Without it they cannot connect; for a proxy server, mounts treat the proxy group as unreachable and read and write object storage directly.

To rotate certificates:

  1. Replace the certificate and key files at the configured paths.
  2. Restart the server process. The new certificate will be loaded on startup.

Connected clients reconnect automatically after the restart.