tencent cloud

문서Global Accelerator 2.0

Certificate Management

다운로드
포커스 모드
폰트 크기
마지막 업데이트 시간: 2026-09-04 16:28:44
AI 번역

Overview

An HTTPS certificate (also known as an SSL/TLS certificate), a digital certificate issued by a trusted certificate authority (CA), is used to verify the identity of a website and enable encrypted connections. It uses the SSL/TLS protocol to establish a secure tunnel between the client (such as a browser) and the server, ensuring the confidentiality (anti-eavesdropping), integrity (anti-tampering), and authenticity (anti-spoofing) of data transmission. The certificate contains the website's public key, domain name, CA information, and validity period. When you use Global Accelerator 2.0 (GA2.0) to create an HTTPS listener, you need to upload and manage the certificate.

Authentication Modes

You can select the HTTPS authentication mode for a GA2.0 listener instance as needed. Both one-way authentication and mutual authentication are supported, and the core difference between them lies in the direction and strictness of identity authentication.
One-way authentication: The client verifies the server's identity, but the server does not verify the client's identity. In this authentication mode, you only need to upload the server certificate to GA2.0. This mode is suitable for public services such as general website browsing and e-commerce platforms, where users do not need to pre-configure certificates.
Mutual authentication: The client and the server verify each other's identities. In this authentication mode, you need to upload both the server certificate and the client certificate to GA2.0. This mode is suitable for high-security scenarios such as enterprise private networks, financial systems, and medical data exchange, where only clients holding valid certificates are allowed to access the service.
Comparison Item
One-Way Authentication
Mutual Authentication
Verifier
Only the client verifies the server.
Both parties verify each other.
Client certificate
Not required.
Required.
Security
Moderate (anti-eavesdropping and anti-tampering).
Higher (anti-spoofing and anti-MITM attacks).
Complexity
Simple configuration is required. You only need to upload the server certificate.
You need to upload both the server certificate and the client certificate.
Typical application
Ordinary websites.
Banking systems and internal APIs.

Certificate Types

Certificate types are categorized into default server certificates, custom server certificates, and CA certificates. You only need to upload and manage CA certificates when you select the mutual authentication mode.
Certificate Type
Description
Default server certificate
The default certificate is the server certificate uploaded when a listener is created. When a client request does not match any other custom server certificates, GA2.0 returns the default certificate for HTTPS authentication.
The default certificate can only be replaced, but cannot be deleted or added.
One HTTPS listener has exactly one default certificate.
Custom server certificate
When you need to use a GA2.0 instance to accelerate multiple HTTPS domain names, you can add multiple custom certificates to the listener, with each certificate corresponding to a different domain name.
Note:
A custom certificate can be replaced. The domain name of the new certificate that replaces the existing one must be consistent with the domain name of the existing one. Otherwise, the replacement cannot be completed.
CA certificate
When you select mutual authentication as the authentication mode, in addition to the server certificate, you also need to upload the CA certificate to verify the legitimacy of the client's identity.
The CA certificate can be replaced, but cannot be deleted or added.
One HTTPS listener has exactly one CA certificate.

Associated Domain Names

GA2.0 allows you to add multiple domain name certificates for one HTTPS listener to achieve flexible management during multi-domain name acceleration. When adding a custom server certificate, you need to create an association between the certificate and the domain name. After the association is created, GA2.0 returns the corresponding certificate based on the domain name of the client request. If no domain name contained in the custom certificate is matched, the default certificate is returned.

Uploading a Certificate

Prerequisites

A GA2.0 instance and an HTTPS listener have been created.

Operation Steps

1. Log in to the GA2.0 console.
2. On the instance list page, click the target instance ID and go to the instance details page.
3. On the listener tab, click the target listener ID to go to the listener details page.
4. Click Certificate Management to go to the certificate management tab.
5. Click Add Certificate. In the pop-up window, complete the configurations.
Configuration Item
Description
Certificate Type
The type of the added certificate. Only custom server certificates can be added.
Server Certificate
The certificate to be added. You can manage the certificates in a unified way in the SSL console.
Associated Domain Name
The domain name contained in a server certificate. GA2.0 returns the corresponding certificate based on the domain name of the client request.

Replacing a Certificate

1. Log in to the GA2.0 console.
2. On the instance list page, click the target instance ID and go to the instance details page.
3. On the listener tab, click the target listener ID to go to the listener details page.
4. Click Certificate Management to go to the certificate management tab.
5. Click Replace Certificate on the right of an existing certificate to replace it.
Note:
When you replace a custom server certificate, the domain names of the new and existing certificates must be consistent. Otherwise, the replacement cannot be completed. When you replace the default certificate or the CA certificate, domain name consistency is not required.

Deleting a Certificate

1. Log in to the GA2.0 console.
2. On the instance list page, click the target instance ID and go to the instance details page.
3. On the listener tab, click the target listener ID to go to the listener details page.
4. Click Certificate Management to go to the certificate management tab.
5. Click Delete on the right of the existing custom server certificate.
6. In the pop-up window, click Confirm to complete the deletion.
Note:
The default certificate cannot be deleted.

References

도움말 및 지원

문제 해결에 도움이 되었나요?

피드백