RadiusNest › Guides

MikroTik hotspot HTTPS login page: certificate, setup and warnings

Last updated: 2 October 2026

The hotspot login page can be served over HTTPS so that passwords are encrypted on the way to the router. It needs a real certificate for a real domain name. Done with a self-signed certificate it makes things worse, not better.

Is it worth it?

  • Worth it on open Wi-Fi where customers type usernames and passwords they use for a long time, and you own a domain name.
  • Not needed for one-time voucher codes on a small site. The default page already protects the password with CHAP, which sends a scrambled value instead of the password itself.
  • It does not fix the HTTPS redirect. A customer who opens an https:// site before logging in still gets a warning or a blank page, because the router cannot hold a certificate for somebody else's site. See login page not opening.

Why a self-signed certificate causes warnings

A browser trusts a certificate only if it was issued by an authority the browser already knows, for exactly the name in the address bar. A certificate you make on the router is signed by nobody the phone knows, so every customer sees "your connection is not private" before your login page. Most will stop there. The same happens with a real certificate if the name does not match, or after it has expired.

What you need

  1. A domain name you own, and a host name under it for the hotspot, for example login.example.com.
  2. A certificate for that exact name from a public certificate authority. Because the login page is only reachable from inside your network, choose a method of proving ownership that works through DNS records.
  3. Two files: the certificate with its chain (often fullchain.pem) and the private key (privkey.pem).
  4. The right time on the router (System → Clock), or valid certificates are reported as invalid.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

1. Import the certificate

Drag both files into Files in Winbox, then:

/certificate import file-name=fullchain.pem passphrase=""
/certificate import file-name=privkey.pem passphrase=""
/certificate print

In the list, the certificate for your host name must show the flag K (it has its private key). Note its name, for example fullchain.pem_0. Delete the two files from Files afterwards; the key should not lie around.

2. Set the name and the certificate in the hotspot profile

/ip hotspot profile set hsprof1 dns-name=login.example.com ssl-certificate=fullchain.pem_0 login-by=https,cookie,http-chap,http-pap

dns-name must be exactly the name in the certificate. The router answers that name with its own hotspot address for clients, so you do not need to publish an address for it on the internet.

3. Test

  1. Connect a phone, let the sign-in window open and log in.
  2. Open https://login.example.com/login in a browser. The padlock must show with no warning.
  3. Try a second browser and a second phone. A warning on some devices only usually means the chain file is incomplete.
/ip hotspot profile print
/log print where topics~"hotspot"

Remember the renewal

Certificates expire, some after 90 days. When yours expires, every customer gets a warning in place of the login page. Put the date in your calendar, import the new files the same way, point ssl-certificate at the new entry and remove the old one:

/certificate print
/certificate remove [find name="fullchain.pem_0"]

Going back to plain HTTP

/ip hotspot profile set hsprof1 login-by=cookie,http-chap,http-pap ssl-certificate=none

Your edited pages are not affected; see customizing the login page. If you have not built the hotspot yet, start with hotspot setup.

Where RadiusNest fits

The login page and its certificate belong to your router, and RadiusNest does not change them. RadiusNest checks the username and password the router passes on, for hotspot and PPPoE and for several routers at once. Customers also have their own self-service page where they see their balance.

Start the free trial See pricing

Questions and answers

Can I use a free certificate for the hotspot login page?

Yes, any certificate from a public authority works if it is issued for the exact dns-name of the hotspot and you import it with its key and chain.

Does HTTPS login stop the certificate warning on HTTPS sites?

No. That warning comes from the site the customer tried to open, not from your login page. Phones avoid it by opening their own sign-in window.

Why do customers see a warning after I enabled HTTPS login?

The certificate is self-signed, expired, missing its chain, or issued for a different name than the hotspot dns-name. A wrong router clock has the same effect.

Related guides

Start the free trial See pricing