--- since: 1.0.6 --- # SSL Runbook ## Generate or repair certificates ```bash dplay certs ``` Then: ```bash dplay ssl ``` ## Certificate location ```text ~/.dplay/ssl/localhost.crt ~/.dplay/ssl/localhost.key ``` ## Force regeneration manually The `certs` command removes the current certificate and key before invoking certificate generation again. ## OpenSSL requirement Verify: ```bash openssl version ``` If OpenSSL is missing, the CLI reports: ```text openssl not found on this system. ``` ## SAN behavior The certificate always includes: ```text DNS:localhost DNS:*.localhost IP:127.0.0.1 ``` It also includes configured host/subdomain entries. ## Trust failures Trusting the certificate is best-effort. If automatic trust fails, the development server can still run, but the browser may show a certificate warning. The platform-specific trust steps are: ```text macOS → System Keychain Linux → /usr/local/share/ca-certificates + update-ca-certificates WSL → Linux trust store + Windows certutil ```