Help Center/ Config/ User Guide/ Resource Compliance/ Built-In Policies/ Elastic Load Balance/ ELB Listeners Are Bound with CCM-Managed Certificates
Updated on 2025-12-04 GMT+08:00

ELB Listeners Are Bound with CCM-Managed Certificates

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

elb-ccm-certificate-enabled

Identifier

ELB Listeners Are Bound with CCM-Managed Certificates

Description

If the certificate bound to an ELB listener is not managed by CCM, the listener is non-compliant.

Tag

elb

Trigger Type

Configuration change

Filter Type

elb.listeners

Rule Parameters

None

Application Scenarios

When you add an HTTPS or TLS listener, you need to bind a server certificate to it. To enable mutual authentication, you also need to bind a CA certificate to the listener. You can purchase a server certificate from Huawei Cloud Cloud Certificate & Manager (CCM) or upload your own certificates to the ELB console.

Solution

Bind the SSL server certificates you have purchased on or uploaded to CCM.

Rule Logic

  • If the certificate bound to an ELB listener is not managed by CCM, the listener is non-compliant.
  • If the certificates bound to an ELB listener are all managed by CCM, the listener is compliant.