Frequently Asked Question
Regenerate Certificates after hostname change
Regenerate Certificates after hostname change
When you change the hostname of a Proxmox node (updating /etc/hostname and /etc/hosts) you must regenerate the SSL certificates used by the web UI and API. The following steps will force Proxmox to create new certificates based on the new hostname.
Step‑by‑step procedure
# Edit /etc/hostname and set the new hostname, e.g. newnode01
# Edit /etc/hosts and ensure the new hostname resolves to 127.0.0.1
- Update the hostname files
pvecm updatecerts --force
- Force Proxmox to regenerate its certificates
systemctl restart pveproxy
systemctl restart pvedaemon
- Restart the required services
- Verify the new certificate
openssl s_client -connect newhost:8006 -servername newhost </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer
- Open the web UI (
https://newhostname:8006) and confirm you can log in without a certificate warning. - Alternatively, check the certificate details with:
Common pitfalls
- Missing entry in
/etc/hosts– The hostname must resolve locally; otherwise the certificate generation will still use the old name. - Stale services – If you skip the
systemctl restartcommands, the old certificates may remain cached. - Cluster nodes – On a multi‑node cluster you should run the same commands on every node, then restart the cluster services (
pve-cluster).
What to check next
- Ensure the new hostname is correctly set in both
/etc/hostnameand/etc/hosts. - Confirm that no other services (e.g.,
pve-ha-cron) are still using the old hostname by checking their configuration files.
Following these steps will give you a clean, newly‑issued SSL certificate that matches your updated hostname.
Proxmox support from the engineers who wrote this article
This article came out of a real case resolved by GEN engineers, not from upstream documentation. GEN have run Proxmox in production in our own UK data centres since 2015, and have been in enterprise IT for 37 years. If this one has not solved your problem, we can.
- 30 minute response, 24 hours a day, every day of the year on critical production infrastructure.
- No contracts. Buy hours, use hours. No minimum term and no notice period.
- Genuinely independent. We hold no software partner status with Proxmox or any other vendor, so nothing we recommend is shaped by a licence margin.
- UK based, in-house engineers. No outsourced first line.
Proxmox support · VMware to Proxmox migration · Proxmox training · Support rates
Registering a GEN account is free, so the route to an engineer is open before you need it. You only ever pay for the time you use.
