tencent cloud

All product documents
Cloud Load Balancer
Managing Certificates
Last updated: 2024-01-04 14:34:05
Managing Certificates
Last updated: 2024-01-04 14:34:05
When configuring an HTTPS listener of a CLB instance, you can directly use a certificate in SSL Certificate Service or upload the third-party server certificate and SSL certificate that you require to the CLB console.

Certificate Requirements

CLB supports only certificates in PEM format. Before uploading a certificate, make sure that your certificate, certificate chain, and private key meet the format requirement. For information about the certificate requirements, see Certificate Requirements and Certificate Format Conversion.

Certificate Encryption Algorithms

CLB supports the following algorithms for certificate encryption: ECC and RSA. For more information about the algorithms, see What are the differences between RSA and ECC?.
Note:
You can configure two certificates that use different algorithms in SSL parsing for HTTPS listeners. For more information, see Configuring an HTTPS Listener.
Listener Type
Supported Encryption Algorithm When Configuring One Certificate
Supported Encryption Algorithms When Configuring Two Certificates
HTTPS
RSA or ECC
RSA and ECC
TCP_SSL, QUIC
RSA or ECC
Does not support configuring two certificates that use different encryption algorithms.
TCP, UDP, HTTP
Does not support configuring certificates.
Does not support configuring certificates.

Configuring Certificates

There are two types of certificate configuration for an HTTPS listener:
Listener-level certificate configuration: If SNI is not enabled, the same certificate is configured for all domain names under the listener. For more information, see Configuring an HTTPS Listener.
Domain name-level certificate configuration: If SNI is enabled, different certificates can be configured for different domain names under the listener. For more information, see SNI Support for Binding Multiple Certificates to a CLB Instance.

Updating Certificates

To prevent certificate expiration from affecting your service, please update your certificate before it expires.
Note:
After a certificate is updated, the system does not delete the legacy certificate but generates a new one. The certificate will be automatically updated for all CLB instances that use it.
1. Log in to the CLB console.
2. Click Certificate management in the left sidebar.
3. In the certificate list, click Update in the Operation column of the target certificate.
4. In the pop-up window, enter the content and key of the new certificate and click Submit.


Viewing CLB Instances Associated with a Certificate

1. Log in to the CLB console.
2. Click Certificate management in the left sidebar.
3. In the certificate list, click the ID of the target certificate.
4. On the Basic information page, view the CLB instances associated with the certificate.


Was this page helpful?
You can also Contact Sales or Submit a Ticket for help.
Yes
No

Feedback

Contact Us

Contact our sales team or business advisors to help your business.

Technical Support

Open a ticket if you're looking for further assistance. Our Ticket is 7x24 available.

7x24 Phone Support
Hong Kong, China
+852 800 906 020 (Toll Free)
United States
+1 844 606 0804 (Toll Free)
United Kingdom
+44 808 196 4551 (Toll Free)
Canada
+1 888 605 7930 (Toll Free)
Australia
+61 1300 986 386 (Toll Free)
EdgeOne hotline
+852 300 80699
More local hotlines coming soon