# Hot reload of certificates

**URL:** <https://openziti.discourse.group/t/hot-reload-of-certificates/5192>\
**Category:** BrowZer\
**Created:** [October 4, 2025, 4:45pm UTC](https://openziti.discourse.group/t/hot-reload-of-certificates/5192 "2025-10-04T16:45:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmuensterer](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/dmuensterer/32/2451_2.png) [@dmuensterer](https://openziti.discourse.group/u/dmuensterer)\
**Post date:** [October 4, 2025, 4:45pm UTC](https://openziti.discourse.group/t/hot-reload-of-certificates/5192/1 "2025-10-04T16:45:01Z")

</div>

Hi,

is it currently necessary to restart the controller if the public alternative certificate is renewed? We didn’t find a way yet to renew our Let’s Encrypt certs except for restarting the Ziti Controller? Is there a way to “gracefully” restart so that the connections aren’t just cut, but all entities expect the controller to go down and back up again?

Thanks

Dominik

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [October 6, 2025, 11:46am UTC](https://openziti.discourse.group/t/hot-reload-of-certificates/5192/2 "2025-10-06T11:46:52Z")

</div>

That's a good question. I am sure the normal fields of the identity block are watched for changes, but I'm not sure if the alt certs are. I'll ask @andrew.martinez to have a look and comment. He knows that section of ziti best.

---

<div class="post-metadata">

**Author:** ![andrew.martinez](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/andrew.martinez/32/540_2.png) [@andrew.martinez](https://openziti.discourse.group/u/andrew.martinez)\
**Post date:** [October 6, 2025, 12:58pm UTC](https://openziti.discourse.group/t/hot-reload-of-certificates/5192/3 "2025-10-06T12:58:10Z")

</div>

Can you confirm which version of the controller you are on?

---

<div class="post-metadata">

**Author:** ![andrew.martinez](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/andrew.martinez/32/540_2.png) [@andrew.martinez](https://openziti.discourse.group/u/andrew.martinez)\
**Post date:** [October 6, 2025, 1:04pm UTC](https://openziti.discourse.group/t/hot-reload-of-certificates/5192/4 "2025-10-06T13:04:25Z")

</div>

In the most recent versions, as long as the cert/key, server cert/key, alter server cert/key are a file, they should be watched. There are warning messages output if they cannot be for some reason on controller startup.

Once I have you version I can confirm if this is the same behavior in the version you are running. I know within the last year or so this was enabled for alt server certs/keys and there were some platform specific bugs (I believe in linux).

---

<div class="post-metadata">

**Author:** ![dmuensterer](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/dmuensterer/32/2451_2.png) [@dmuensterer](https://openziti.discourse.group/u/dmuensterer)\
**Post date:** [October 6, 2025, 1:28pm UTC](https://openziti.discourse.group/t/hot-reload-of-certificates/5192/5 "2025-10-06T13:28:00Z")

</div>

I was running v1.5.4 when the issue occurred. Now upgraded to v1.6.8 which probably means that the hot reload works? Will test, thanks
