Home Support Documentation Privacy Terms Licenses

Overview

Introduction How it works

Get started

Prerequisites Marketplace install Entra prerequisites Admin authorization Setup wizard Hostname & TLS

Operate

Daily operations Updates & plans Restricted networks

Troubleshoot

Recover admin access

Legal

Open source notices

Support

Get help

Hostname & TLS

Last updated: 20 September 2026

Goal: Serve Sandman on your production hostname with a trusted certificate.

After the wizard, sign in at https://<public-ip>/ (your browser may warn about the temporary certificate). As a Sandman admin, open Settings:

  1. Custom Domain — Enter the hostname where your team will reach Sandman. Create a DNS A record pointing to the server IP.
  2. TLS Certificate — Choose Let’s Encrypt (HTTP-01 or DNS-01), upload a PEM certificate, or remain on IP-only/self-signed for testing.
  3. Entra redirect URI — Update the app registration to https://<hostname>/auth/callback.
Sandman Settings Custom Domain tab — DNS steps and hostname field.
Figure 4. Settings → Custom Domain — DNS A record and hostname configuration.
Sandman Settings TLS Certificate tab — Let's Encrypt or upload PEM.
Figure 5. Settings → TLS Certificate — trusted HTTPS for production.

Configure Teams notifications later under Settings → Notification when ready.

Verify: https://<hostname>/ loads without certificate warnings (or with your uploaded cert), and Microsoft sign-in completes.

© 2026 Sandman