All Tools View Categories About Contact Privacy

Nginx Multi-Domain SSL Config Generator

Emit SNI server blocks for several domains on one certificate.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your multi-domain SSL blocks will appear here.
-
lines
-
blocks

About Nginx Multi-Domain SSL Config Generator

When several domains share a single wildcard or SAN certificate, the cleanest nginx setup is one SNI server block per domain, all referencing the same cert files. Hand-writing that repetition invites mismatched server_name lines, a certificate path that drifts, or a protocol list that is empty on one block. The Nginx Multi-Domain SSL Config Generator emits one validated 443 ssl server block per domain, sharing the certificate prefix, then re-parses the whole result.

At the heart of the configuration are a handful of directives. ssl_certificate points each block at the shared fullchain.pem from the certificate prefix. ssl_certificate_key references the shared privkey.pem for the certificate. ssl_protocols limits negotiated versions to TLSv1.2 and/or TLSv1.3 across every block. listen binds each block to 443 ssl for encrypted SNI-based virtual hosting. server_name selects the correct block per domain via the TLS SNI extension. ssl_session_cache reuses TLS sessions to speed up handshakes across all domains. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. An empty protocol list would make the server unable to negotiate, so the generator forbids disabling both TLS 1.2 and 1.3. A certificate path that is not absolute makes nginx fail to start, so the tool requires a leading slash. A bad domain in the list would break the server block, so every domain is validated before generation. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

For teams, a generated block is also documentation. New engineers can read the exact directives in place, compare them against the sample, and learn the relevant nginx behaviour without reverse-engineering a hand-maintained file that drifted from its original intent.

Features

  • ssl_certificate - points each block at the shared fullchain.pem from the certificate prefix.
  • ssl_certificate_key - references the shared privkey.pem for the certificate.
  • ssl_protocols - limits negotiated versions to TLSv1.2 and/or TLSv1.3 across every block.
  • listen - binds each block to 443 ssl for encrypted SNI-based virtual hosting.
  • server_name - selects the correct block per domain via the TLS SNI extension.
  • ssl_session_cache - reuses TLS sessions to speed up handshakes across all domains.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. List each domain on its own line.
  2. Set the certificate path prefix to the absolute directory with the shared cert.
  3. Choose which TLS versions to allow.
  4. Click Generate (or Load sample) and review the blocks.
  5. Confirm one server block per domain was emitted.
  6. Drop it into conf.d and run nginx -t.
  7. Reload nginx to apply the SNI blocks.

Examples

Example 1 - Two domains a.example.com and b.example.com each get a block sharing one cert - a standard SAN host.

Example 2 - Single domain one domain still emits a valid standalone 443 ssl block.

Example 3 - Bad domain rejected a domain with a space is reported before generation.

Example 4 - Relative cert path a cert prefix without a leading slash is rejected as an error.

Example 5 - No TLS rejected disabling both TLS versions is reported as an error.

Benefits

  • One validated block per domain, sharing one cert.
  • Correct SNI-based server_name selection.
  • Shared certificate prefix avoids drift.
  • Safe protocol list that can never be empty.
  • Self-checked output re-parsed before display.
  • Private: everything runs in your browser.

Frequently Asked Questions

What is SNI here?
Each domain gets its own server block; nginx uses the TLS SNI extension to pick the right one even though they share one certificate.
Why share one certificate?
A wildcard or SAN certificate covers several domains, so reusing it keeps config small and renewal simple.
Do all blocks need the cert?
Yes - every server block references the same fullchain.pem and privkey.pem from the shared prefix.
How many domains can I add?
As many as the certificate covers; the generator emits one block per domain you list.
Can I mix TLS versions?
Yes - toggle TLS 1.2 and 1.3; the generator forbids enabling neither.
Where do certificates come from?
Obtain them with certbot or your CA; the tool only references the paths.
Is the output validated?
Yes - the combined blocks are re-parsed before display.
Is anything uploaded?
No. Everything runs locally in your browser.