---
title: Charmhub | Deploy TLS Certificates Operator using Charmhub - The Open Operator
  Collection
description: Deploy the latest version of TLS Certificates Operator on any cloud.
url: https://charmhub.io/tls-certificates-operator/configurations
---

# TLS Certificates Operator

[Canonical Telco](https://charmhub.io/publisher/telco-charmers "View all packages from Canonical Telco")

* [Canonical Telco](https://charmhub.io/publisher/telco-charmers "View all packages from Canonical Telco")

Platform:

22.04

20.04

stable 22

```
juju deploy tls-certificates-operator
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [ca-certificate](https://charmhub.io/tls-certificates-operator/configurations#ca-certificate)
* [ca-chain](https://charmhub.io/tls-certificates-operator/configurations#ca-chain)
* [ca-common-name](https://charmhub.io/tls-certificates-operator/configurations#ca-common-name)
* [certificate](https://charmhub.io/tls-certificates-operator/configurations#certificate)
* [certificate-validity](https://charmhub.io/tls-certificates-operator/configurations#certificate-validity)
* [generate-self-signed-certificates](https://charmhub.io/tls-certificates-operator/configurations#generate-self-signed-certificates)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* ca-certificate | string

  Base64 encoded CA Certificate (do not use if 'generate-self-signed-certificates' is set to true).
* ca-chain | string

  Base64 encoded CA chain (do not use if 'generate-self-signed-certificates' is set to true).
  If not provided, the ca-chain will be composed of the application and the ca-certificate.
  The `ca_chain.pem` file should have the following format:
  -----BEGIN CERTIFICATE-----
  (Your Primary SSL certificate)
  -----END CERTIFICATE-----
  -----BEGIN CERTIFICATE-----
  (Your Intermediate certificate)
  -----END CERTIFICATE-----
  -----BEGIN CERTIFICATE-----
  (Your Root certificate)
  -----END CERTIFICATE-----
* ca-common-name | string

  Common name to be used only if `generate-self-signed-certificates` set to true.
* certificate | string

  Base64 encoded TLS certificate (do not use if 'generate-self-signed-certificates' is set to true).
* certificate-validity | int

  Default: 365

  Certificate validity (in days) only if `generate-self-signed-certificates` set to true.
* generate-self-signed-certificates | boolean

  Generate self-signed certificates and ignores provided certificates.
