Origin certificates
An origin certificate is a certificate we make for one zone, for you to install on your origin server. With Verify Origin SSL Certificate on, our servers trust your origin when it presents that exact certificate, so the connection is encrypted and verified without a public certificate authority, whatever address, port or hostnames the zone uses. It does not expire.
When to use one#
- Your origin is reached at an IP address and port rather than a hostname a public authority issues certificates for.
- Your origin has no public certificate, or a self-signed one.
- You add and remove hostnames on the zone and do not want your origin's certificate to follow them.
An origin that already has a publicly trusted certificate for your site does not need one: Verify Origin SSL Certificate accepts that as it is.
Create one#
On the zone page, in the Origin Certificate box below Origin Details, press Create origin certificate. The zone needs an https:// origin; a private bucket origin does not use one. The new certificate and its private key are shown, each with Copy and Download. Save the key now: it is shown only this once and is not kept anywhere, so if it is lost, reissue the certificate. The certificate stays in the box, to copy or download again whenever you need it.
Creating one breaks nothing. Until it is installed, your origin's current certificate is still accepted if a public authority issued it for your site.
Install it on your origin#
Install the certificate and the key as your web server's HTTPS certificate for the site. Both are PEM files, which every web server reads. With nginx:
ssl_certificate /etc/ssl/video-origin.pem;
ssl_certificate_key /etc/ssl/video-origin.key;With Apache:
SSLCertificateFile /etc/ssl/video-origin.pem
SSLCertificateKeyFile /etc/ssl/video-origin.keyWith IIS, combine the two into a PFX file, import it into the server's certificate store and bind it to the site on port 443:
openssl pkcs12 -export -in video-origin.pem -inkey video-origin.key \
-out video-origin.pfxReload the web server, then turn on Verify Origin SSL Certificate in the zone's CDN Settings if it is off. To see which certificate your origin serves, compare the fingerprint this prints with the one in the Origin Certificate box:
openssl s_client -connect 203.0.113.10:443 -servername cdn.example.com \
</dev/null | openssl x509 -noout -fingerprint -sha256What it checks#
- With Verify Origin SSL Certificate on, your origin passes when it presents the zone's origin certificate, or a certificate a public authority issued for the hostname asked for. Anything else is refused, and the visitor gets a 502.
- With it off, nothing is checked, origin certificate or not: the connection is encrypted but not verified.
- It is trusted by its fingerprint, the SHA-256 of the whole certificate, for this zone alone. Its names and dates are not read, so a hostname added to the zone later works without a new certificate. It carries the zone's hostnames from when it was made, for hosting control panels that install a certificate by the domain it names.
- Browsers do not trust it. It is for the connection between our servers and your origin: your visitors see the certificate of the hostname they asked for.
Reissue or revoke#
Reissue makes a new certificate and key, and our servers stop trusting the old one within a few seconds, so install the new one at once: until you do, your origin is trusted only if it has a public certificate for your site. Reissue when the private key may have been exposed, or when it has been lost.
Revoke stops our servers trusting the certificate within a few seconds and removes it from the zone. It cannot be trusted again: to use an origin certificate after that, create a new one. While a zone has an origin certificate its origin has to stay https://, so revoke it first to change the origin to http://.
Through the API, see Origin certificates in the API section.