> ## Documentation Index
> Fetch the complete documentation index at: https://3to1go.docs.thesteau.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Trusted certificates

> Let Central and Edge verify internal HTTPS services signed by your own CA.

If an HTTPS service an app connects to uses a private CA, add that CA to the app's trust list. For example, Edge needs to trust Central's CA, and each app needs to trust its ntfy server's CA. Each app keeps its own list.

This configures outbound trust. It does not enable HTTPS on either web UI or make your browser trust a private CA; configure HTTPS at your reverse proxy and browser separately.

## Upload from the UI

<Steps>
  <Step title="Open settings">
    Open **Edit Central Settings** in Central, or **Edit Edge Settings** in Edge.
  </Step>

  <Step title="Add the certificate">
    Under **Trusted Certificates**, upload your CA or root certificate as a PEM `.crt` file. Each app supports up to ten uploaded certificate files.
  </Step>
</Steps>

The app saves it under `/config/trusted-certs`, installs it into the container's trust store immediately, and reinstalls it every time the container starts.

## Add files directly

For automated deployments, drop `.crt` files into the app's persisted config folder before starting it:

```text theme={null}
3to1go-central/config/trusted-certs/home-ca.crt
3to1go-edge/config/trusted-certs/home-ca.crt
```

This keeps your certificates out of the image while letting the apps verify private HTTPS endpoints.

<Note>
  Only CA or root certificates are needed, not each server's certificate. Files must end in `.crt`.
</Note>
