Updated on 2026-10-10 GMT+08:00

Determining the SSL Certificate Installation/Deployment Solution

SSL certificates can be installed or deployed on the server or client.

  • Installing/Deploying an SSL Certificate on a Server (mandatory): If your website or application provides HTTPS encrypted access, you must install or deploy the certificate on the server to configure an encrypted connection.
  • Installing the Certificate on a Client (optional): If users access your web services through a client, such as Java, download the root certificate and manually install it on the client because the client does not have a built-in root certificate. This ensures that the client can verify the encrypted information of your web server.

This section describes how to select an SSL certificate installation/deployment solution for the server. For details about the scenarios and operations for installing the root certificate on the client, see Installing the Root Certificate on a Client.

Prerequisites for Installing/Deploying an SSL Certificate on the Server

Procedure

  1. Determine the installation or deployment location of the certificate.

    The SSL certificate must be deployed on the node where HTTPS traffic terminates. That is, the certificate must be deployed at the layer responsible for completing the HTTPS handshake, traffic decryption, and verification between the client and intermediate nodes.
    • Direct server connection: If public network traffic connects directly to your origin web server, you only need to install the SSL certificate on that web server.
      Figure 1 Direct server connection
    • Traffic passing through multiple nodes: Deploy the certificate on whichever layer that completes the HTTPS handshake, traffic decryption, and verification. The following uses the combination architecture (User device → CDN → WAF → ELB → Origin server) as an example to describe the certificate deployment locations.
      Figure 2 Traffic passing through multiple nodes via encrypted connections (User device → CDN → WAF → ELB → Origin server)
      Table 1 Certificate deployment nodes for different encrypted connections when traffic passes through multiple nodes (User device → CDN → WAF → ELB → Origin server)

      Encrypted Connection (HTTPS)

      Plaintext Connection

      Core Node for Certificate Deployment

      Node Requiring No Deployment

      Advantage

      User device → CDN

      CDN → WAF → ELB → Origin server

      CDN

      WAF, ELB, and origin server

      Only one set of certificates needs to be maintained, reducing deployment and renewal workloads while ensuring low access latency.

      User device → CDN → WAF

      WAF → ELB → Origin server

      CDN, WAF

      ELB and origin server

      It provides comprehensive web attack detection, ensuring both acceleration and application-layer security.

      User device → CDN → WAF → ELB

      ELB → Origin server

      CDN, WAF, ELB

      Origin server

      ELB can distribute HTTPS traffic in a refined manner to improve security.

      User device → CDN → WAF → ELB → Origin server

      -

      CDN, WAF, ELB, and origin server

      -

      No plaintext data is transmitted, ensuring the highest level of security.

  2. Install/Deploy an SSL certificate.