Domain/SSL
The Settings > Domain/SSL pane is used to configure the domain name, SSL, and Edge Remote endpoint in Belden Horizon Data Manager. This pane includes the following sections:
- Domain
- SSL settings
- Edge Remote
Domain Features
You can use the domain name to obtain access to Belden Horizon Data Manager without knowing the IP address. This helps when configuring settings:
- Base domain name: The basic domain name is used by clients accessing the Belden Horizon Data Manager Admin Console, Belden Horizon Data Manager Application, and Keycloak application.
Before You Begin
Ensure a DNS server exists to handle requests by clients using the domain name.

[1] Edit Base Domain Name: Changing the domain name can cause connection issues such as disconnecting all previously connected edge devices. It is recommended that you make DNS changes prior to configuring the rest of your settings. The domain name also causes an update to the certificates. It may be necessary to accept new certificates after reloading the current browser tab. See Browser Access Restrictions for more information.
- If the domain name is valid, a green check mark displays.
- If the domain name is invalid, a red exclamation mark displays.
[2] Copy base domain name
[3] View Domain Log: Enabling auto-scroll is helpful when running an import process.
[4] Save base domain name
SSL Setting Features
There are three options when selecting a SSL setting:
- Instance Default Certificate: Allows you to use the default self-signed SSL certificate that is automatically created during deployment when you first boot up for HTTPS, and MQTT SSL.
- Let's Encrypt Webroot mode: The certificate is based on Let's Encrypt using their Webroot mode. You must enter the domain name for your web-server in the Domain section. An IP address cannot be used. This is used when the web-server is exposed to the Internet and should not be used for private networks.
- User Defined: The SSL encryption uses a self-signed certificate (.crt or .pem file) and a (.key or .pem file) that has been uploaded to Belden Horizon Data Manager. The same certificate must be uploaded to the connected edge device.

[5] Select SSL Setting
- Select Instance Default Certificate to ensure that the SSL certificates that are used for the server and instances are valid and trusted by the server.
- Select Let's Encrypt Webroot mode to secure publicly available content in a domain by encryption, and then click Save. It issues a certificate when ownership is proven. This selection requires that a domain name is set. This selection cannot be used with an IP address.
- Select User Defined to use an SSL certificate and key file to secure content. A .crt or .pem file and a .key or .pem file is required for this selection.
[6] (User-Defined Only) Upload SSL Certificate
[7] (User-Defined Only) Key file
[8] (User-Defined Only) Root CA Certificate
[9] View SSL Log: Enabling auto-scroll is helpful when running an import process.
[10] Save SSL Settings
Edge Remote
The Edge Remote endpoint is the location of the Belden Horizon Data Manager remote service that forms a private secured connection between this Belden Horizon Data Manager instance and all of its associated Belden Horizon Data Operations devices. This endpoint can be used for a DNS or an IP address.
By default and in most circumstances, the Edge Remote endpoint will be identical to the Belden Horizon Data Manager instance's IP address/DNS.
The only exception is when the Belden Horizon Data Manager is deployed on Google Kubernetes Engine. In this deployment situation, the IP address of the Belden Horizon Data Manager and the IP address of the LEM remote service will differ. The IP address of the Belden Horizon Data Manager remote service will be generated by Kubernetes and should be set as the Edge Remote endpoint accordingly. If a DNS is associated with the IP address received from Kubernetes, then the DNS should likewise also be set as the Edge Remote endpoint accordingly. Setting the DNS this way prevents the need to reactivate Belden Horizon Data Operations devices when the Belden Horizon Data Manager IP address changes.
Refer to the following actions you can take on Belden Horizon Data Manager Admin Console's Domain/SSL pane.

[11] Edit Edge Remote
[12] Copy Edge Remote endpoint
[13] Save Edge Remote endpoint: You can only save when the DNS/IP address is valid.