Private PKI and Sign Certificates

A private service (such as a site or app) still needs a way to prove it's the service you meant to reach.

September 30, 2026

PKI is the certificate system that makes that trust possible.

Verify the identity of your doxx.net services with certificates from doxx.net’s private certificate authority. That lets your private services use authenticated, encrypted connections without relying on a public certificate authority to recognize a .doxx name.

1.Features

  • Verify the identity of services using eligible doxx.net domain names.
  • Use certificates signed by doxx.net's own certificate authority in order to encrypt traffic.
  • Support authenticated HTTPS connections to private services.
  • Keep the service's private key on the machine where it was generated.

doxx.net certificates do not apply for external TLDs such as .com and .org.

2.To sign a certificate to your site or service

  • Navigate on the portal to: DNS and PKI → Sign Certificate.
  • On the machine that your service/website is hosted on:
    • Generate a CSR key using OpenSSL (The specific command written in the doxx.net portal).
  • Paste the CSR into the doxx.net portal.
  • doxx.net will create your website’s certification.
  • Paste it back into your machine and now you have an official doxx.net signed certificate.

Anyone with the doxx.net Root CA installed will be able to access your website/service freely and easily

Imported public domains need an appropriate public certificate authority instead.

If you configured your network agent, you can ask it to do it for you or configure yourself in the doxx.net portal.

3.Common Questions

What's the difference between PKI and a domain certificate?

PKI is the system behind certificate issuance and trust. A domain certificate is an individual credential that helps identify the service you’re connecting to.

Which domains can use these certificates?

Domains you own within the supported doxx.net namespace. Imported public names such as .com and .org are outside this private certificate authority's signing scope.

Will getting a certificate make my service private?

No. A certificate helps verify identity and establish a secure connection. Network access rules still decide who can reach the service.

Why does my browser still show a warning?

The device or browser may not trust the doxx.net root CA yet. A warning can also mean the certificate is expired or doesn't match the name you're visiting. Check the cause instead of bypassing the warning.

Can my agent configure the certificate?

An authorized network agent can use the documented certificate-signing tools. It also needs the appropriate access to configure the service that will use the certificate.