Use a shared cert hostname (HTTPS)

The ‚ÄčAkamai‚Äč shared certificate ("shared cert") enables secure delivery over HTTPS using a proprietary certificate that ‚ÄčAkamai‚Äč maintains.

How Edge IP Binding works with a shared cert hostname

You define a prefix value and enable Edge IP Binding in a secure property hostname. The prefix is automatically combined with a fixed domain value, akamaized.net to form your secure edge hostname. Once your property is activated, you have an edge hostname that points directly to ‚ÄčAkamai‚Äč edge servers and several Edge IP Binding IP addresses that you use as follows:

  • Use the edge hostname directly in access URLs. Provide them to your end users to directly access your content via HTTPS, using ‚ÄčAkamai‚Äč's proprietary shared certificate.

  • Provide the Edge IP Binding IP addresses to your third party. They use them for zone-rated billing. HTTPS requests to these IP addresses access your property in the same way the edge hostname does.

Understand the connections

There are two connections involved in a request using the ‚ÄčAkamai‚Äč platform:

  • The client to ‚ÄčAkamai‚Äč edge server. This is the initial HTTPS connection between the end user and the edge server to get your property. The property determines how to deliver the requested content. This is the connection you're configuring here, in the property hostname to support Edge IP Binding.

  • The ‚ÄčAkamai‚Äč edge server to origin. This is the connection between the edge server and your designated origin, to get your content and deliver it to the end user. To configure this connection, you set options in the Origin Server behavior in your property. More on this later.

Implementation

Follow these steps to add Edge IP Binding in a shared cert hostname.

  1. Ensure that Enhanced TLS or Shared Cert is selected in Security Options.
  1. In the Property Hostnames content panel, click the dropdown menu next to the Add button and select Shared Certificate Hostname.

  2. Enter your desired prefix value in the Edge Hostname field. Use alphanumeric or hyphen characters, with a total length of 4-60 characters. You can't start this prefix with a hyphen.

  3. Select the appropriate IP version, based on what your application or site can support, and click Next.

  4. Select Edge IP Binding as the Mapping Solution and click Next.

ūüďė

If you're using Adaptive Media Delivery or Download Delivery, you'll also have access to the Use Case option, Segmented Media Mode or FOREGROUND, respectively. These are not supported for use with Edge IP Binding.

Verify status and finish your property

The status of your new Edge IP Binding configuration is shown in the Property Hostnames panel:

  • The Status icon is gray. Activation of your Edge IP Binding addresses is pending.

  • The Status icon is green. Your addresses have been provisioned and are ready. You can use them after your property has been activated on ‚ÄčAkamai‚Äč's staging (testing) or production (live) networks.

ūüďė

It can take from 30 - 40 minutes to generate your Edge IP Binding addresses.

Perform these steps to complete the process:

  1. You can optionally add variables.

  2. You need to define property configuration settings that include rules to match requests and the behaviors that should be applied. Available rules and behaviors vary, based on the product you're using:

  3. There are two connections in a request. The process here addressed the first connection between the end user and ‚ÄčAkamai‚Äč edge servers. You need to configure the second connection between an edge server and the origin server to get content. Set up this connection using the Origin Server behavior in a rule in your property.

  4. Activate the property on the staging network where you can test it, and then activate it on production.

  5. Optionally, you can create the following alerts:

    • DNS does not contain an authorized certificate authority.
    • Domain validation failed.
    • Certificate‚Äôs domain is blocked.
    • Expired default certificate.
    • Expired default certificate removal.