# Custom certificate not loaded

**URL:** <https://forums.plex.tv/t/custom-certificate-not-loaded/925315>\
**Category:** Plex Media Server\
**Tags:** server-qnap\
**Created:** [July 8, 2025, 1:08am UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315 "2025-07-08T01:08:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![razvanpascal](https://avatars.discourse-cdn.com/v4/letter/r/d07c76/32.png) [@razvanpascal](https://forums.plex.tv/u/razvanpascal)\
**Post date:** [July 8, 2025, 1:08am UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/1 "2025-07-08T01:08:52Z")

</div>

Server Version#:1.41.8  
Player Version#:  
\<If providing [server logs](https://support.plex.tv/articles/200250417-plex-media-server-log-files/) please do NOT turn on verbose logging, only [debug logging](https://support.plex.tv/articles/201643703-reporting-issues-with-plex-media-server/#toc-1) should be enabled\>

QNAP QTS 5.2.5.3162

Jul 08, 2025 03:00:53.082 [139859573508752] DEBUG - MyPlex: using cached data for request for [https://plex.tv/api/v2/server/users/features](https://plex.tv/api/v2/server/users/features)  
Jul 08, 2025 03:00:53.121 [139859573508752] DEBUG - [CERT] Subject name is /CN=_.9ce48d2d227dac.plex.direct  
Jul 08, 2025 03:00:53.121 [139859573508752] DEBUG - [CERT] Installed certificate with fingerprint 0b:aa:60:e9:55.  
Jul 08, 2025 03:00:53.121 [139859573508752] DEBUG - [CERT/OCSP] no URL available  
Jul 08, 2025 03:00:53.121 [139859573508752] WARN - [CERT/OCSP] getCertInfo failed; skipping stapling  
Jul 08, 2025 03:00:53.126 [139859573508752] DEBUG - [CERT] Loaded a user-provided certificate for /CN=_.man.de.  
Jul 08, 2025 03:00:53.126 [139859573508752] WARN - [CERT/OCSP] Missing cert or issuer; skipping stapling  
Jul 08, 2025 03:00:53.126 [139859573508752] DEBUG - HttpServer: Listening on IPv6 as well as IPv4.

I am trying to install my custom certificate.  
I have tried various ways and lost a night, but no resolution. Anyone knows what is the issue?

 ![Screenshot 2025-07-08 031048](https://global.discourse-cdn.com/plex/original/4X/5/b/2/5b29ffaddacface57a3b55b22314265761d5b75b.png)

---

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [July 8, 2025, 1:52am UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/2 "2025-07-08T01:52:48Z")

</div>

PMS must also have the CA’s cert included in the P12 in order to accept it.

Self-signed certificates are not accepted.

---

<div class="post-metadata">

**Author:** ![razvanpascal](https://avatars.discourse-cdn.com/v4/letter/r/d07c76/32.png) [@razvanpascal](https://forums.plex.tv/u/razvanpascal)\
**Post date:** [July 8, 2025, 9:10am UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/3 "2025-07-08T09:10:35Z")

</div>

Thank you for your reply.  
How would I do that in PMS? Or do I have it done in QTS Ubuntu?

---

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [July 8, 2025, 3:23pm UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/4 "2025-07-08T15:23:19Z")

</div>

You create the P12 externally to PMS first.

My cert is from Let’s Encrypt, managed by Pfsense and the ACME management software in PfSense

```auto
openssl pkcs12 -export -out my-domain.p12 -inkey my-domain-production.key -in my-domain-production.crt \
        -certfile Acme-LE.crt \
        -password pass:password

```

I put the p12 where PMS can read it

---

<div class="post-metadata">

**Author:** ![razvanpascal](https://avatars.discourse-cdn.com/v4/letter/r/d07c76/32.png) [@razvanpascal](https://forums.plex.tv/u/razvanpascal)\
**Post date:** [July 9, 2025, 12:32am UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/5 "2025-07-09T00:32:08Z")

</div>

Thank you. It worked by adding CA certificate into the mix.

---

<div class="post-metadata">

**Author:** ![folofjc](https://avatars.discourse-cdn.com/v4/letter/f/ea5d25/32.png) [@folofjc](https://forums.plex.tv/u/folofjc)\
**Post date:** [August 6, 2025, 6:52pm UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/6 "2025-08-06T18:52:12Z")

</div>

@ChuckPa I use the acme.sh script with letsencrypt. I get an “intermediate CA cert” and a “full chain cert” file. Which one should I use with the `certfile` option in openssl?

This is the error I am getting:

```auto
Aug 06, 2025 21:05:01.114 [140572162636432] DEBUG - [CERT] Subject name is /CN=*.stuff.plex.direct
Aug 06, 2025 21:05:01.114 [140572162636432] DEBUG - [CERT] Installed certificate with fingerprint ##:##
Aug 06, 2025 21:05:01.114 [140572162636432] DEBUG - [CERT/OCSP] no URL available
Aug 06, 2025 21:05:01.114 [140572162636432] WARN - [CERT/OCSP] getCertInfo failed; skipping stapling
Aug 06, 2025 21:05:01.114 [140572162636432] ERROR - [CERT] Found a user-provided certificate, but couldn't install it.

```

When I create the certificate using the `acme.sh` script, when I specify the domain, I use `-d *.mydomain.com` because I want not only `plex.mydomain.com` but `anything.mydomain.com`. So in the Settings-\>Network, what should I use for the “Custom certificate domain”?

---

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [August 6, 2025, 9:42pm UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/7 "2025-08-06T21:42:21Z")

</div>

@folofjc

When you get an ACME cert, it’s based on the CA from the provider.

That CA is all you need with your CRT and KEY.

“Full Chain” stuff ie messy.

Also … **DO NOT** supersede `plex.direct`. You will break it.  
`plex.direct` is an INTERNAL domain, tied to your Plex-issued cert, which expires every 30 days, and is used by PMS and players for DDNS resolution

---

<div class="post-metadata">

**Author:** ![folofjc](https://avatars.discourse-cdn.com/v4/letter/f/ea5d25/32.png) [@folofjc](https://forums.plex.tv/u/folofjc)\
**Post date:** [August 7, 2025, 6:31am UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/8 "2025-08-07T06:31:55Z")

</div>

Okay, I tried that and it didn’t work. Should I upload my logs?

About the plex direct stuff, I edited the log. I wasn’t sure if that and the fingerprint are supposed to be private, so I just obscured the log when I posted it here. I did not mess with the `plex.direct` stuff in reality.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)\
**Post date:** [November 5, 2025, 6:32am UTC](https://forums.plex.tv/t/custom-certificate-not-loaded/925315/9 "2025-11-05T06:32:52Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
