Updated on 2026-09-17 GMT+08:00

Updating a System Web Certificate

Scenarios

A web certificate for a bastion host is a Secure Sockets Layer (SSL) server digital certificate issued by a trusted root certificate authority (CA). The certificate is used to verify the website identity and secure connections.

A secure self-issued certificate is configured for each bastion host by default, but this certificate takes effect only within certain scope and period. You can replace it with your own certificate.

This topic describes how to update the system certificate if it expires or fails a security check.

Prerequisites

  • You have purchased and downloaded an SSL certificate.
  • The domain name the uploaded certificate is used for has been resolved to the EIP bound to the bastion host. For details, see Adding Record Sets for a Public Zone.
  • The role you belong to has the management permission for the System module. For details about how to check the permissions of each role, see Role.

Notes and Constraints

  • Currently, only the Java Keystore certificate file of Tomcat, that is, the certificate file in .jks is supported.
  • Currently, the bastion host system supports the following certificate cryptographic algorithms: RSA and ECDSA.
  • A certificate file cannot exceed 20 KB and must contain a certificate password. When you upload an SSL certificate, provide its password for verification, or the upload will fail.

Manually Updating the System Web Certificate

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose System > System Config > Security.
  3. In the Web Certificate configuration area, click Edit. The Web Certificate upload dialog box is displayed.
  4. Set Update Type to Upload.
  5. Upload the certificate file downloaded in your computer.
  6. After the certificate file is uploaded, enter the Keystore password to verify the certificate.
  7. (Optional) For a primary/standby bastion host instance, select Synchronize Uploading The Certificate To The Standby Machine. After this option is selected, the uploaded web certificate file will be synchronized to the standby server and take effect.
  8. Click OK. You can then check the web certificate configuration of the current system user on the Security tab.

Enabling Automatic Web Certificate Rotation

To ensure the security and stability of the system, you need to periodically replace the security certificate. However, manual certificate replacement is time-consuming and may interrupt services. If you enable certificate rotation, the bastion host system automatically generates a self-signed certificate and overwrites the current certificate before the certificate expires.

If the bastion host is deployed in primary/standby mode, the standby bastion host automatically rotates the certificate periodically after you enable certificate rotation for the primary bastion host.

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose System > System Config > Security.
  3. In the Web Certificate configuration area, click Edit. The Web Certificate upload dialog box is displayed.
  4. Set Update Type to Certificate Rotation.
  5. Click OK.

FAQs

If the browser still says the system is insecure after you update an SSL certificate, fix the issue by referring to Why Does the Browser Still Consider the Website Insecure While the Website Has an SSL Certificate Deployed?