SSL/TLS Setup
Serve the ScanSuite console over a custom certificate, or behind a web server the host already runs.
Serve the ScanSuite console over a custom certificate. If you also run the DefectDojo integration, it is a separate installation with its own domain and certificate — see Set up DefectDojo (Optional).
1. Register a domain name
Register a domain for the console in DNS, for example scansuite.yourdomain.com.
2. Stop the server
Before applying the certificate, stop ScanSuite:
cd /opt/scansuite && ./scansuite stop3. Obtain a certificate
Obtain a certificate from the local Certificate Authority. If the ScanSuite server is publicly accessible, you can use Let's Encrypt instead.
Install Certbot
sudo snap install certbot --classicGenerate the certificate
sudo certbot certonly --register-unsafely-without-email --agree-tos -d scansuite.yourdomain.com4. Replace the key and certificate
Copy the newly generated certificate and key to /opt/scansuite/services/nginx/certs/. Ensure the file names cert.pem and key.pem are preserved.

5. Start the server
cd /opt/scansuite && ./scansuite restart6. Verify the certificate loaded
Check the nginx logs to confirm the certificate loaded correctly:
cd /opt/scansuite && docker compose logs nginxIf any errors appear, double-check the certificate paths and permissions. A certificate managed by certbot lives outside the certs directory, so the nginx configuration has to point at it — see Setup parameters and services.
Behind a web server the host already runs
When the host already serves ports 80 and 443 — its own nginx or Apache, or a proxy in front of several sites — keep the certificate there and let that server forward to ScanSuite. Publish the console on the loopback address and switch off ScanSuite's own nginx in docker-compose.local.yml, next to docker-compose.yml:
services:
web:
ports:
- "127.0.0.1:5000:5000"
ai_docs:
ports:
- "127.0.0.1:4000:4000"
nginx:
profiles: ["bundled-nginx"]The file belongs to the host: updates never change it, and install, update and start always include it. Apply it with a restart; ./scansuite doctor then reports that ports 80 and 443 are left to the host.
cd /opt/scansuite && ./scansuite restartPoint the host's web server at those ports. For nginx:
server {
listen 443 ssl;
server_name scansuite.yourdomain.com;
ssl_certificate /etc/letsencrypt/live/scansuite.yourdomain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/scansuite.yourdomain.com/privkey.pem;
client_max_body_size 2000M;
proxy_read_timeout 600;
proxy_send_timeout 600;
location / {
proxy_pass http://127.0.0.1:5000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /aidocs/ {
proxy_pass http://127.0.0.1:4000;
proxy_set_header Host $host;
}
}Keep the body size and the timeouts, which are the ones ScanSuite's own nginx uses: code archives and reports are uploaded through the console, and without them the proxy cuts large uploads and long requests short with 413 and 504 errors.
Last reviewed 2026-09-27