Updated on 2026-10-10 GMT+08:00

Downloading an SSL Certificate

After an SSL certificate is issued, you can install it on a web server. You need to download the SSL certificate first. Then, upload the downloaded certificate to the web server and modify the server configuration for the SSL certificate to take effect.

This topic describes how to download an SSL certificate on the SCM platform.

Prerequisites

The certificate is in the Issued or Hosted status.

Constraints

  • A certificate can only be downloaded when it is in its validity period.
  • If you select System generated CSR for CSR, the downloaded file package contains folders Apache, IIS, Nginx, Tomcat, and Pem and file domain.csr.
  • If you select Upload a CSR for CSR, the downloaded file package contains only file server.pem. The file contains two segments of certificate code, namely, the server certificate and intermediate CA certificate. Huawei Cloud SCM does not store your private keys. Keep them safe. If the certificate private key needs to be included in the downloaded file, upload the private key (optional).

(Optional) Uploading a Private Key

  1. Log in to the CCM console.
  2. In the navigation pane on the left, choose SSL Certificate Manager > SSL Certificates.
  3. In the Operation column of the certificate for which you want to upload a private key, choose More > Upload Private Key.
  4. In the displayed Upload Private Key dialog box, click Upload to upload the private key file, or paste the private key below Private Key.

  5. Click Submit. If Private key uploaded successfully is displayed in the upper right corner of the page, the private key has been uploaded.

Procedure

  1. Log in to the CCM console.
  2. In the navigation pane on the left, choose SSL Certificate Manager > SSL Certificates.
  3. In the Operation column of the row containing the desired certificate, click Download.

    Figure 1 Downloading a certificate

  4. On the download certificate page, confirm the certificate information and click Download.
  5. Install the certificate on the corresponding server for the SSL certificate to work.

    The procedure for installing an SSL certificate varies depending on the web server. The following describes how to install an SSL certificate on mainstream web servers.

Description of Downloaded Certificate Files

Downloaded certificate files vary depending on what you selected for CSR (System generated CSR or Upload a CSR) when you applied for your certificate.

  • System generated CSR
    The downloaded certificate package contains Apache, IIS, Nginx, Tomcat, and Pem folders as well as the domain.csr file. For details, see Figure 2. Table 1 shows an example.
    Figure 2 Decompressing an SSL certificate package
    Table 1 Description of files/folders in the downloaded certificate

    File/Folder Name

    Content

    Tomcat

    keystorePass.txt: certificate password

    server.jks: certificate file

    Nginx

    server.crt: certificate file, which contains two segments of certificate code (server certificate and intermediate CA certificate respectively)

    server.key: certificate private key file, which contains a segment of private key code of the certificate

    Apache

    ca.crt: certificate chain file, which contains a segment of intermediate CA code

    server.crt: certificate file, which contains a segment of server certificate code

    server.key: certificate private key file, which contains a segment of private key code of the certificate

    IIS

    keystorePass.txt: certificate password

    server.pfx: certificate file

    Pem

    chain.pem: certificate file, which contains a segment of CA certificate code

    private_key.pem: certificate private key file, which contains a segment of certificate private key code

    server.pem: certificate file, which contains a segment of server certificate code

    domain.csr

    Certificate signing request

  • Upload a CSR

    The downloaded certificate package contains only the server.pem file. The file contains two segments of certificate code, namely, the server certificate and intermediate CA certificate.

    Huawei Cloud SCM does not store your private keys. Keep them safe. When installing the certificate on a server, you will need to provide the file path to the location of your private keys.

    If you select Upload a CSR for CSR, the certificates cannot be directly deployed in other cloud services.

Checking the Server Type

Before installing an SSL certificate on a server, you need to determine the server type. This section describes how to check the server type.

Method 1: Query the Server Type Using a Browser

This method may fail to obtain the server type, or the obtained server type may be inaccurate. If any of the following problems occurs, use other methods to check the server type:
  • The server information may be hidden. For security purposes, website O&M personnel may modify or delete the server information in the response headers. In this case, the Server field may not exist, or it may be displayed as a user-defined value.
  • The server type may be inaccurate. If the website uses proxy services such as CDN and ELB, the Server field displays the proxy server type rather than the true origin server type.
  1. Open the developer tool.

    Open a browser (for example, Chrome), access the target website, right-click anywhere on the page and choose Inspect from the shortcut menu, or press F12 to open the developer tool.

  2. Switch to the Network tab.

    On the top menu bar of the developer tool, click Network to switch to the Network tab.

  3. Load the resource list.

    Refresh the target website page. All resources on the page will be loaded on the Network tab.

  4. Check the server response header.

    1. In the resource list, click the main request at the top of the list (usually the first line of the domain name, with the Type set to document).
    2. On the displayed details panel, click the Headers tab.
    3. In the Response Headers area, search for the Server field. The value of this field usually indicates the server type and version.

Method 2: Log In to the Server

Log in to the website server and check the web server type. For a Windows OS:

  1. Press Win+R, enter resmon, and press Enter. Start the Resource Monitor.
  2. On the Resource Monitor page, click Network.
  3. On the Network tab, click Listening Ports. Locate the entries whose port is 80 or 443, and identify the web server based on the process information in the Name column.

Method 3: Consult Website Engineers

If the web server type cannot be obtained using the preceding two methods, consult website development engineers or O&M engineers.