Adding an SSL Certificate for an API
If the API group contains HTTPS-compatible APIs, add an SSL certificate for the independent domain name bound to the group. An SSL certificate is used for data encryption and identity authentication. Both one-way authentication and two-way authentication are supported. If no SSL certificate is configured, the request security cannot be ensured. You are advised to configure an SSL certificate.
- One-way authentication: When connecting to the server, a client verifies whether the server is correct.
- Two-way authentication: When connecting to a server, a client verifies the server and the server also verifies the client.
Constraints
- Only SSL certificates in PEM format are supported.
- SSL certificates support only the RSA and ECDSA encryption algorithms.
Prerequisites
- You have obtained the SSL certificate.
- If two-way authentication is used, you also need to obtain the CA certificate.
Adding an SSL Certificate
- Go to the APIG console.
- Select a dedicated gateway at the top of the navigation pane.
- In the navigation pane, choose API Management > API Policies.
- On the SSL Certificates tab, click Create SSL Certificate.
- Configure the certificate according to the following table.
Table 1 SSL certificate configuration Parameter
Description
Name
Enter an SSL certificate name. It is recommended that you enter a name based on naming rules to facilitate search.
Enter 4 to 50 characters, starting with a letter. Only letters, digits, and underscores (_) are allowed.
Gateways Covered
Certificate display scope.
- Current: The certificate will be displayed only for the current gateway.
- All: The certificate will be displayed for all gateways of the current account in the current region.
Algorithm
Specify the cryptographic algorithm used by the certificate. Options: RSA or ECC.
- Rivest–Shamir–Adleman (RSA) is an asymmetric cryptographic algorithm that is widely used around the world. It features high compatibility and supports mainstream browsers and all platform OSs. Generally, RSA uses a 2048-bit or 3072-bit key.
- Elliptical curve cryptography (ECC) features faster encryption, higher efficiency, and lower server resource consumption compared with RSA. ECC is being promoted in mainstream browsers and is becoming a new-generation mainstream algorithm. Generally, ECC uses a 256-bit key.
Content
SSL certificate content in PEM format.
- Open the target PEM certificate file using Notepad or other tools, and copy the certificate content to Content.
- If the certificate is not in PEM format, convert it to this format.
Key
SSL certificate key in PEM format.
Open the KEY or PEM private key file using Notepad or other tools, and copy the private key to Key.
CA
For two-way authentication, you need to enter the CA certificate to verify both the server and client certificates. After the CA certificate is uploaded, the independent domain name needs to be bound to an SSL certificate to enable two-way authentication. Open the CA certificate file (.pem format) corresponding to the preceding certificate content as a text file and copy the CA content to CA.
- If the certificate is not in PEM format, convert it to this format.
- If the current gateway does not support CA certificates, submit a service ticket to upgrade it.
- Click OK.
If the created certificate is displayed in the certificate list, the certificate is created successfully.
- After creating a certificate, bind it to an independent name of an API group. For details, see (Optional) Binding an SSL Certificate.
To modify a certificate, see Updating an SSL Certificate.
Converting Certificate Format to PEM
| Format | Converting with OpenSSL |
|---|---|
| CER/CRT | Rename the certificate file cert.crt cert.pem. |
| PFX |
|
| P7B |
|
| DER |
|
Updating an SSL Certificate
On the certificate list page, locate the certificate to be updated, click Modify in the Operation column, and modify the certificate information.
- Updating the SSL certificate does not affect API calling.
- If the certificate to be updated has been bound to an independent domain name, all clients that access the domain name can view the updated certificate.
- If the updated SSL certificate has been bound to an independent domain name, the client authentication (HTTPS two-way authentication) is disabled by default when a CA certificate is added to the updated content.
Related Documents
To create an SSL certificate by calling an API, see Creating an SSL Certificate.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot

