What to read next Changing the Default Certificate of the ControllerThe Avi Load Balancer Controller can be accessed through the UI using the default certificate associated with it, but users get a warning message regarding certificate mismatch or certificate trust. To avoid a browser warning message while accessing the Controller, install the complete certificate chain matching the FQDN of the Controller and replace the default Controller certificate with the new certificate. Renew Default (Self-Signed) Certificates on Avi Load BalancerThe default certificate on Avi Load Balancer is self-signed. This section explains how to replace the default certificate when the certificate is expired or is about to expire. The following steps can also be used to replace the self-signed certificate with a third-party signed certificate. Configure Stronger SSL CipherThis section explains how to Configure Stronger SSL Cipher. User Interface Inaccessible Due to Wrong CertificateThere can be instances where the Avi Load Balancer user interface is not accessible, but the Controller is reachable through CLI access. Import Encrypted Private Key to Install an SSL CertificateYou can import an encrypted private key to install an SSL certificate on Avi Load Balancer. Password associated with an encrypted private key can be provided using the Key Passphrase option, available in the Avi Load Balancer UI while creating an SSL certificate. Avi Load Balancer uses the provided passphrase to decrypt the private key while installing the SSL certificate. Venafi IntegrationThe Avi Load Balancer can be set up to integrate with the Venafi Trust Protection Platform™ for automation of SSL and TLS certificate life-cycle management. All certificates will be protected and controlled through TPP. This process is transparent to the Avi Load Balancer Controllers. Integrating Let's Encrypt Certificate Authority with Avi Load BalancerLet’s Encrypt is a free, automated (automates both issuing and renewing the certificate) and open certificate authority. The following section describes integration of Let's Encrypt Certificate Authority with Avi Load Balancer. Certificate Management Integration for CSR AutomationAvi Load Balancer supports automation of the process for requesting and installing a certificate signed by a certificate authority (CA). This feature handles initial certificate registration and renewal of certificates based on certificate expiration. This topic explains configuring certificate management integration and automatic certificate renewal. SSL CertificatesAvi Load Balancer supports terminating client SSL and TLS connections at the virtual service, which requires it to send a certificate to clients that authenticate the site and establishes secure communications. Parent topic: CLI Access Settings