Updating the Certificate Used for a Website
If you use cloud CNAME or dedicated mode access mode for website access and set Client Protocol to HTTPS, you need to upload a certificate to WAF and associate the certificate with your protected website.
If the certificate is about to expire, you are advised to update it before it expires. This prevents certificate-related issues, such as WAF protection rule failures and website access exceptions. To prevent service faults caused by certificate expiration, you can configure WAF alarm notifications to receive certificate expiration notifications and update the certificate in a timely manner.
Constraints
- Each domain name must have a certificate associated. A wildcard domain name can only use a wildcard domain certificate. If you only have single-domain certificates, add domain names one by one in WAF.
- Only .pem certificates can be used in WAF. If the certificate is not in .pem, before uploading it, convert it to .pem by referring to Related Operations.
- Only IAM users with SCM Administrator and SCM FullAccess permissions can select SCM certificates.
- Before updating the certificate, ensure that your WAF instance and the certificate you want to upload belong to the same account.
Impact on the System
- It is recommended that you update the certificate before it expires. Otherwise, all WAF protection rules will fail to take effect, and there can be massive impacts on the origin server, even more severe than a crashed host or website access failures.
- Updating certificates does not affect services. The old certificate still works during the certificate replacement. The new certificate will take over the job once it has been uploaded and successfully associated with the domain name.
- Access to your website may be affected when you update the configurations of certificates used for backend servers or for domain names of your websites protected by WAF. To minimize these impacts, update the certificates during off-peak hours.
Procedure
| Step | Description |
|---|---|
| Step 1: Configure Certificate Expiration Alarm Notifications | Receive the expiration alarm, check the certificate status, and plan the certificate update window. |
| Step 2: Apply for or Renew an SSL Certificate on a CA Platform | Apply for certificate renewal, verify the domain name ownership, and obtain the certificate. Convert the certificate into a PEM certificate file supported by WAF. |
| Import the new certificate to WAF and ensure that the certificate status is normal. | |
| Submit the certificate replacement request. WAF switches to the new certificate seamlessly without interrupting services. | |
| Verify website access, certificate information, and service functions and make sure that the new certificate takes effect and protection is normal. |
Prerequisites
- You have added your website to WAF and selected HTTPS for Client Protocol.
- You have enabled alarm notifications.
Step 1: Configure Certificate Expiration Alarm Notifications
- Configure WAF alarm notifications in advance.
If you have configured WAF certificate expiration alarm notifications, SMN will send notifications to you through SMS messages or emails based on the expiration reminder window duration and notification frequency you configured.
- Check the alarm information.
After receiving a certificate expiration alarm, you can check the protected domain name, expiration time of the certificate used for it, and certificate type in the protected object list to confirm that the certificate is really about to expire and eliminate false alarms.
- Make an update plan.
Reserve sufficient time for the operation based on the certificate expiration time. Update the certificate during off-peak hours, such as early mornings and weekends, to avoid operational risks during peak hours.
Step 2: Apply for or Renew an SSL Certificate on a CA Platform
You can apply for a certificate from our Cloud Certificate & Manager (CCM) or other certificate authorities (CAs). After obtaining the certificate file and private key, you can use it in WAF. This section describes how to apply for or renew an SSL certificate from Huawei Cloud CCM.
- Applying for an SSL Certificate
- Renew an SSL certificate. For details, see Certificate Lifecycle Management.
Step 3: Upload a Certificate to WAF
If the certificate you applied for from Huawei Cloud CCM has been pushed to WAF, you do not need to upload it again.
- Log in to the WAF console.
- Click
in the upper left corner and select a region or project. - (Optional) If you have enabled the enterprise project function, in the upper part of the navigation pane on the left, select your enterprise project from the Filter by enterprise project drop-down list. Then, WAF will display the related security data in the enterprise project on the page.
- In the navigation pane on the left, choose .
- Above the certificate list, click Add Certificate.
- On the Add Certificate panel, configure the following parameters and click OK.
Table 1 Adding an international certificate. Parameter
Description
Example Value
Certificate Type
Select the type of the certificate to be added. Select International.
Chinese
Certificate Name
Enter a certificate name.
waf_international
Certificate File
Public key certificate file, which is in PEM format and contains public information such as the public key, protected domain name, validity period, and CA. WAF delivers the certificate to the client during an HTTPS handshake for site identity verification and key encryption.
Open the .pem file in the certificate you want to add as a text file and copy the certificate content in the file to the text box.
-----BEGIN CERTIFICATE-----
MIIDIjCCAougAwIBAgIJALV96mEtVF4EMA0GCSqGSIb3DQEBBQUAMGoxCzAJBgNVBAYTAnh4MQswCQYDVQQIEwJ4eDELMAkGA1UEBxMCeHgxCzAJBgNVBAoTAnh4MQswCQYDVQQLEwJ
-----END CERTIFICATE-----
Private Key
Private key paired with the certificate file. The private key is in PEM format and stored in WAF. It is used to decrypt the session key and handshake signature. It is highly sensitive information and must be kept confidential. The certificate file must match the private key. Otherwise, the upload will fail.
Open the .key file in the certificate you want to add as a text file and copy the private key in the file to the text box.
-----BEGIN RSA PRIVATE KEY-----
MIICXQIBAAKBgQDFPN9ojPndxSC4E1pqWQVKGHCFlXAAGBOxbGfSzXqzsoyacotueqMqXQbxrPSQFATeVmhZPNVEMdvcAMjYsV/mymtAwVqVA6q/OFdX/b3UHO+b/VqLo3J5SrM
-----END RSA PRIVATE KEY-----
Check whether the certificate matches the private key.
Select this option. If the certificate does not match the private key, click Why Does My Certificate Not Match the Private Key?
-
Step 4: Update the Certificate Used for a Website
- Log in to the WAF console.
- Click
in the upper left corner and select a region or project. - (Optional) If you have enabled the enterprise project function, in the upper part of the navigation pane on the left, select your enterprise project from the Filter by enterprise project drop-down list. Then, WAF will display the related security data in the enterprise project on the page.
- In the navigation pane on the left, choose .
- On the Protected Objects page, click the target domain name.
- Click Modify next to the certificate name. On the Update Certificate panel, import a new certificate or select an existing certificate.
- If you have uploaded a certificate to WAF, select Select existing certificate for Update Method and select the certificate that has been uploaded to WAF from the certificate drop-down list.
- If you have not uploaded a certificate to WAF, select Import new certificate for Update Method and enter the certificate name, certificate file, and certificate private key. For details, see Uploading a Certificate to WAF.
- If the certificate was applied for through Huawei Cloud CCM and has been pushed to WAF, select SCM certificate for Update Method and select the corresponding certificate from the certificate drop-down list.
Step 5: Verify HTTPS Access
- Basic access verification: Use a browser to access the domain name of the protected website. Refresh the page multiple times. Ensure that the website can be loaded properly, no access timeout occurs, no blank page is displayed, and no redirection exception occurs.
- Certificate information verification: Click the certificate icon in the address bar of the browser to view the certificate details. Check the certificate serial number, validity period, and CA. Ensure that the displayed certificate is the new one and the expiration time has been updated.
- Security verification: Check that the HTTPS connection of your website does not have any insecure warning (typically in red), no security warning indicating certificate expiration or mismatch, and the TLS connection is established properly.
- Service function verification: Test the core access and interaction functions of your website. Ensure that the WAF protection rules are working properly, no protection or blocking exceptions occur, no service errors are reported, and the certificate update process is complete.
Related Operations
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot