- What's New
- Function Overview
- Service Overview
-
SSL Certificate Manager (SCM)
- About SCM and SSL Certificate Usage
- Purchasing an SSL Certificate
- Applying for an SSL Certificate
- Deploying SSL Certificates
-
Managing SSL Certificates
- Reissuing an SSL certificate
- Unsubscribing from an SSL Certificate
- Renewing an SSL Certificate
- Revoking an SSL Certificate
- Deleting an SSL Certificate from CCM
- Uploading an External Certificate to SCM
- Adding an Additional Domain Name
- Withdrawing an SSL Certificate Application
- Canceling Authorization for Privacy Information
- Pushing an SSL Certificate to Other Cloud Services
- Viewing Details About an SSL Certificate
- Viewing the Application Progress
- Permissions Management
- Change History
-
Private Certificate Authority (PCA)
- Overview of Private Certificate Application
- Private CA Management
-
Private Certificate Management
- Applying for a Private Certificate
- Downloading a Private Certificate
-
Installing a Private Certificate
- Trusting a Private Root CA
- Installing a Private Certificate on a Client
-
Installing a Private Certificate on a Server
- Installing a Private Certificate on a Tomcat Server
- Installing a Private Certificate on an Nginx Server
- Installing a Private Certificate on an Apache Server
- Installing a Private Certificate on an IIS Server
- Installing a Private Certificate on a WebLogic Server
- Installing a Private Certificate on a Resin Server
- Revoking a Private Certificate
- Viewing Details of a Private Certificate
- Deleting a Private Certificate
- Permissions Management
- Change History
- API Reference
-
FAQs
-
FAQs
-
Certificate Consulting
- What Are the Differences Between SSL Certificate Manager and Private Certificate Authority?
- Which Websites Require HTTPS?
- What Are the Differences Between HTTPS and HTTP?
- What Is a Public Key and a Private Key?
- What Are the Relationships Between a Public Key, Private Key, and Digital Certificate?
- Why Is a Non-Password-Protected Private Key Required?
- What Are Mainstream Formats of Digital Certificates?
- What Information Does an SSL Certificate Contain?
- Can I Use SSL Certificates for Other Regions, Accounts, or Platforms?
- Can I Use an Unused SSL Certificate Anytime I Want?
- Can SSL Certificates Be Upgraded?
- Does the SSL Certificate Have Restrictions on the Server Port?
- Why Is the Service Displayed as Inaccessible or the Button Displayed in Gray When I Access the SCM Service on the Console?
-
SSL Certificate Application and Purchase
-
SSL Certificate Selection
- Does SCM Provide Free Certificates?
- How Do I Select an SSL Certificate?
- How Can I Apply for a Free SSL Certificate?
- What Can I Do If My Free Certificate Quota Is Used Up?
- How Do I Query the Remaining Quota for Free SSL Certificates?
- How Do I Apply for an Entry-Level SSL Certificate?
- What Are Differences Between Free and Paid SSL Certificates?
- How Do I Apply for a Combination Certificate?
- Can I Change the Certificate Authority, Type, or Bound Domain After A Certificate Is Purchased?
- Problems Related to Certificate Purchases
- How Do I Apply for an SSL Certificate That Uses SM Series Cryptographic Algorithms?
-
About Required Domain Name Details
- How Do I Enter a Domain Name for a Certificate When Applying for an SSL Certificate?
- What Are the Differences Between a Single-Domain Name, Multi-Domain Name, and Wildcard-Domain Name in SCM?
- What Is the Relationship Between a Domain Name and an SSL Certificate?
- What Domains Can Wildcard-Domain Certificates Support?
- What Domain Name Should I Use to Apply for an SSL Certificate?
- Can I Change the Primary Domain Name Associated with a Certificate?
- Does the Relationship Between the Primary Domain Name and Additional Domain Name Have Any Impact on Domain Names?
- How Do I Make a CSR File?
- What Are the Differences Between the CSR Generated by the System and the CSR Made by Yourself?
- Domain-related Concepts
- Problems Related to Domains
-
SSL Certificate Selection
- SSL Certificate Approval
-
SSL Certificate Download, Installation, and Use
-
SSL Certificate Use
- Which Region Will a Certificate Be Deployed to When I Deploy an SSL Certificate in CCM to Other Cloud Product?
- Is HTTPS Automatically Enabled After an SSL Certificate Is Deployed to a Cloud Product?
- Why Is a Message Indicating that the Certificate Chain Is Incomplete Displayed When I Configure HTTPS on CDN?
-
SSL Certificate Use
-
Certificate Validity Period
- What Can I Do If My SSL Certificate Expired?
- How Long Is an SSL Certificate Valid?
- What Can I Do If an SSL Certificate Is About to Expire?
- How Long Does an SSL Certificate Take Effect After Being Purchased?
- Validity Periods and Replacement of the Current and New SSL Certificates
- How Can I Renew an SSL Certificate?
- Will Services Be Affected If an SSL Certificate Is Not Updated After It Expires?
- Validity Periods of Private Certificates
- How Long Will an Order Become Invalid If I Do Not Apply for a Certificate After Purchasing It?
- Certificate Management
-
Certificate Consulting
- Change History
-
FAQs
What Can I Do If Domain Ownership Verification Does Not Take Effect?
If you have completed domain name verification but the configuration does not take effect, perform the operations described in this section.
Procedure
- If Domain Name Verification Method is set to DNS, perform the operations described in Configuration Does Not Take Effect After DNS Verification.
- If Domain Name Verification Method is set to File, perform the operations described in Configuration Does Not Take Effect After File Verification.
Prerequisites
- The domain name has been licensed. Obtain the license for the domain name because the domain name verification will fail if the domain name has not been licensed.
- Domain name verification has been configured.
- Check whether the domain name verification takes effect. For more details, see How Do I Check Whether Domain Name Verification Takes Effect?
Configuration Does Not Take Effect After DNS Verification
Locate the failure cause and fix the issue by referring to the following table.
Possible Cause |
Procedure |
---|---|
A wrong domain name management platform was selected. |
DNS verification can be performed only on the platform where your domain name is hosted. Check whether the platform you select is the right one. |
The old record set is not deleted. |
The record added can be deleted once the current certificate is issued. If the record added for the previous certificate is not deleted, the record added for the current certificate will not take effect. Check whether the record added last time is deleted. |
The record configuration is incorrect. |
Check settings of Host Record, Type or Value. |
It requires a long period of time for the configuration to take effect. |
Check whether the effective time (TTL) is too long. It is recommended that you set the TTL to 5 minutes. This value varies depending on the DNS service provider. In our DNS platform, the default value is 5 minutes, so the configuration takes effect in 5 minutes by default. If the configured effective time does not arrive, verify after the time is right. |
Configuration Does Not Take Effect After File Verification
- If the record value displayed on the page is the same as that displayed on the domain name verification page of the SCM console or in the email, the configuration of domain name verification has taken effect.
- If they are different, the configuration of domain name verification does not take effect.
If the configuration does not take effect, check and handle the issue from the following aspects:
- Check whether the verification URL address exists in HTTPS accessible addresses. If yes, use HTTPS to re-access the URL address in the browser. If the browser displays a message indicating that the certificate is untrusted or the displayed content is incorrect, disable the HTTPS service for the domain name temporarily.
- Ensure that the verification URL address can be accessed at any place. Detection servers of some CAs are located outside China. Check whether your site has images outside China or whether the smart DNS service is used.
- Check whether the verification URL address contains 301 or 302 redirection. If such redirection exists, cancel the related settings to disable the redirection.
You can run the wget -S URL address command to check whether the verification URL address is redirected.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.