Skip to main content

TLS (SSL) certificates for CDN resources

A TLS (SSL) certificate is a unique digital signature for a website. A certificate is required for a secure connection between the client and the server (HTTPS protocol) when transferring confidential information and performing financial transactions.

Selectel uses Let’s Encrypt® certificates and custom certificates.

Comparing certificate types

Let’s Encrypt®Personal
DomainsAll CDN resource domainsPersonal CDN resource domains specified in the certificate
ManagementCannot be managedDelete certificate
RenewalAutomaticallyManually

Let’s Encrypt® certificate

A CDN resource can only have one active Let’s Encrypt® certificate, so it must specify all resource domains through which content needs to be distributed over HTTPS. If a domain is not specified in the certificate, content will only be distributed through it over HTTP.

A Let's Encrypt® certificate for default domains becomes active immediately after creating a CDN resource. For personal domains, you must issue a Let's Encrypt certificate manually.

The certificate does not need to be renewed manually; it is automatically reissued 30 days before the expiration date.

A Let’s Encrypt® certificate cannot be deleted, only replaced with a custom certificate.

Read more about Let’s Encrypt® certificate limitations in the Rate Limits section of the Let’s Encrypt® documentation.

Issue a Let’s Encrypt® certificate

  1. Make sure that you created a CDN resource and added a custom domain.

  2. In the control panel, on the top menu, click Products and select CDN.

  3. Go to the Certificates for CDN resources section.

  4. In the menu of the section, click Issue SSL Certificate.

  5. Select the CDN resource for which you want to issue a certificate.

  6. Click Issue.

  7. Go to the CDN Resources section.

  8. Open the CDN resource page → Certificates tab.

  9. Select the HTTPS distribution via CNAME checkbox.

  10. In the Certificate field, select the certificate you issued in step 6.

  11. While settings are being applied, the CDN resource will be in the PROCESSING status. During this time, applying other settings is unavailable. Settings will be applied when the CDN resource transitions to the ACTIVE status.

Personal certificate

A CDN resource can only have one certificate, so it must specify all resource domains through which content needs to be distributed over HTTPS. If a domain is not specified in the certificate, content will only be distributed through it over HTTP.

If you have your own TLS (SSL) certificate, you can upload it as a custom certificate.

Upload custom certificate

  1. Make sure that you created a CDN resource and added a custom domain to the CDN resource.

  2. In the Control panel, in the top menu, click Products and select CDN.

  3. Go to Certificates for CDN resources.

  4. In the section's menu, click Upload custom certificate.

  5. Specify the certificate name. It will only be used in the control panel.

  6. Add the certificate for the custom domain. It must begin with -----BEGIN CERTIFICATE----- and end with -----END CERTIFICATE-----.

    You can add a certificate chain (the primary certificate for the domain, intermediate ones, and the root certificate) — make sure that they form a complete chain. The Issuer value of the primary certificate must match the Subject value of the first intermediate certificate, the Issuer value of the first intermediate certificate must match the Subject of the second intermediate certificate, and so on.

  7. Add the private key of the certificate. It must begin with -----BEGIN PRIVATE KEY----- and end with -----END PRIVATE KEY-----.

  8. Click Upload.

  9. Go to CDN resources.

  10. Open the CDN resource page → tab Certificates.

  11. Select the checkbox Distribute over HTTPS via CNAME.

  12. In the Certificate field, select the certificate that you uploaded in step 8.

  13. While settings are being applied, the CDN resource will be in the PROCESSING status. During this time, applying other settings is unavailable. Settings will be applied when the CDN resource transitions to the ACTIVE status.