Determining the SSL Certificate Installation/Deployment Solution
SSL certificates can be installed or deployed on the server or client.
- Installing/Deploying an SSL Certificate on a Server (mandatory): If your website or application provides HTTPS encrypted access, you must install or deploy the certificate on the server to configure an encrypted connection.
- Installing the Certificate on a Client (optional): If users access your web services through a client, such as Java, download the root certificate and manually install it on the client because the client does not have a built-in root certificate. This ensures that the client can verify the encrypted information of your web server.
This section describes how to select an SSL certificate installation/deployment solution for the server. For details about the scenarios and operations for installing the root certificate on the client, see Installing the Root Certificate on a Client.
Prerequisites for Installing/Deploying an SSL Certificate on the Server
- The certificate is in the Issued or Hosted status.
- Ensure that the certificate matches all the domain names to be protected. For details about how to add or modify a domain name, see How Do I Add, Unbind, Replace, or Change the Domain Name for an SSL Certificate?.
Procedure
- Determine the installation or deployment location of the certificate. The SSL certificate must be deployed on the node where HTTPS traffic terminates. That is, the certificate must be deployed at the layer responsible for completing the HTTPS handshake, traffic decryption, and verification between the client and intermediate nodes.
- Direct server connection: If public network traffic connects directly to your origin web server, you only need to install the SSL certificate on that web server. Figure 1 Direct server connection
- Traffic passing through multiple nodes: Deploy the certificate on whichever layer that completes the HTTPS handshake, traffic decryption, and verification. The following uses the combination architecture (User device → CDN → WAF → ELB → Origin server) as an example to describe the certificate deployment locations. Figure 2 Traffic passing through multiple nodes via encrypted connections (User device → CDN → WAF → ELB → Origin server)
Table 1 Certificate deployment nodes for different encrypted connections when traffic passes through multiple nodes (User device → CDN → WAF → ELB → Origin server) Encrypted Connection (HTTPS)
Plaintext Connection
Core Node for Certificate Deployment
Node Requiring No Deployment
Advantage
User device → CDN
CDN → WAF → ELB → Origin server
CDN
WAF, ELB, and origin server
Only one set of certificates needs to be maintained, reducing deployment and renewal workloads while ensuring low access latency.
User device → CDN → WAF
WAF → ELB → Origin server
CDN, WAF
ELB and origin server
It provides comprehensive web attack detection, ensuring both acceleration and application-layer security.
User device → CDN → WAF → ELB
ELB → Origin server
CDN, WAF, ELB
Origin server
ELB can distribute HTTPS traffic in a refined manner to improve security.
User device → CDN → WAF → ELB → Origin server
-
CDN, WAF, ELB, and origin server
-
No plaintext data is transmitted, ensuring the highest level of security.
- Direct server connection: If public network traffic connects directly to your origin web server, you only need to install the SSL certificate on that web server.
- Install/Deploy an SSL certificate.
- Installing an SSL certificate on a server
- Deploying an SSL certificate to cloud products
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot