Certificate Manager quickstart
Upload your first certificate to Certificate Manager, bind it to a workload, and confirm the platform marks it active.
This guide instructs you through binding your first certificate of your own to a workload with Certificate Manager.
- Upload a server certificate and its private key to Certificate Manager.
- Bind the certificate to your workload.
- Confirm that Certificate Manager reports the certificate as active.
Three objects take part, and each one links to the next:
- The certificate is a server certificate you upload to Certificate Manager with its private key. The API stores it with
typeset toedge_certificate. Its status staysinactiveuntil a workload uses it. - The workload names the certificate in its
tls.certificatefield. While that field isnull, the workload uses the Azion SAN certificate instead. - The domains of the workload are the hostnames the certificate must cover. The API does not compare the certificate’s names with the domains, so a certificate that does not cover them is still accepted.
An uploaded certificate protects no traffic until a workload names it. A workload with no certificate of yours keeps the Azion SAN certificate, which covers only the workload domain and the Azion Custom Domain. This guide changes only the tls settings of the workload and keeps its domains, ports, and deployment as they are.
To have Azion request a certificate from Let’s Encrypt and renew it for you instead, refer to Request a Let’s Encrypt certificate. The workload’s Digital Certificate field also offers the Let’s Encrypt presets, described in Certificates.
Select the interface you use. The prerequisites and every stage on this page follow that choice.
Prerequisites
- An Azion account. To create one, refer to Create an account.
- A workload that lists your domain in its domains. To add a domain, refer to Add a custom domain to a workload.
- A certificate in PEM format that covers your domain, with its private key, also in PEM and without a passphrase. RSA 2048 keys and P-256 keys are accepted.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Upload the certificate
A server certificate holds the certificate and its private key. Once saved, the private key cannot be read back from the Console or the API. You can upload the certificate alone or with its intermediate certificates.
To upload the certificate with the Azion CLI, pass the paths of the two PEM files:
The command prints the ID of the new certificate:
Record the ID to bind the certificate to your workload. List the certificates of your account:
The output shows your certificate with the type edge_certificate and the status inactive:
The certificate exists in Certificate Manager, and no workload uses it yet.
Bind the certificate to your workload
A workload uses a server certificate only once its tls.certificate field names it. Before you bind it, check that the certificate covers the domains of the workload. The API accepts a certificate that does not cover them.
To bind the certificate with the Azion CLI, save the JSON below as tls.json. Replace <workload-id> and <certificate-id>:
The file sends the whole tls object. It names your certificate and keeps the defaults of a new workload, cipher suite 7 and TLS 1.3 as the minimum version. If your workload uses other values, send those instead. Send the file:
The command prints the ID of the workload:
The workload names your certificate in tls.certificate.
Confirm the certificate is active
Certificate Manager reports a certificate as active once a workload names it. The status shows that your workload uses the certificate.
To confirm the status with the Azion CLI, list the certificates of your account:
The output shows your certificate with the status active:
Your certificate is active, and your workload uses it.
Binding a certificate is a change to the workload. The change takes several minutes to reach all of Azion’s distributed infrastructure, with no guaranteed duration. Meanwhile, requests can meet the old configuration or the new one. For more information, refer to Propagation.