--- title: "Veeam Recovery Orchestrator Certificates" description: "To establish a secure connection with a web browser, Veeam Recovery Orchestrator uses an Orchestrator UI certificate. A self-signed Orchestrator UI certificate is generated during installation and used by default." canonical: "https://helpcenter.veeam.com/docs/vro/userguide/certificates.html" breadcrumb: "User Guide > Security Guidelines > Veeam Recovery Orchestrator Certificates" dateModified: "2026-08-26" --- # Veeam Recovery Orchestrator Certificates To establish a secure connection with a web browser, Veeam Recovery Orchestrator uses an Orchestrator UI certificate. A self-signed Orchestrator UI certificate is generated during installation and used by default. If required, you can customize the installation settings and change the certificate. For more information on supported certificates and their requirements, see [Select Certificate for Orchestrator UI](select_vro_certificate.md). To change the certificate after you install Veeam Recovery Orchestrator, add a new certificate to the *Trusted Root Certificate Authorities* and *Local Computer* > *Personal* certificate stores. Then, use the IIS Manager: 1. In the **Sites** section, right-click **Veeam Recovery Orchestrator** **Web UI** and select **Edit bindings**. 2. In the **Site Bindings** window, click **Edit**. 3. In the **SSL certificate** section, click **Select**. 4. Select the certificate from the *Local Computer > Personal* certificate store and click **OK**.