Best practices

Use these best practices when creating and managing your client and account certificates.

  • For both certificate types, it’s strongly suggested that you configure your origin’s trust settings with reference to the CA. This includes the Account CA managed by Akamai or the third-party CA that signed the certificate.
  • Configurations where the trust is established directly with the identity of the client certificate (certificate pinning) are strongly discouraged, as they result in delivery configurations that are difficult to maintain and are likely to cause service disruptions when these client certificates are updated.