Add a hostname with a CCM certificate (Limited Availability)
Create and provision a Cloud Certificate Manager (CCM) certificate or certificate lineage when you add a hostname to a property to easily secure client requests.
Directly from Property Manager, you can bind CCM certificates or certificate lineages to hostnames, configure mutual TLS (mTLS), and deploy secure configurations across Akamai's network. Certificate and certificate lineage management is handled entirely in CCM. See Create a new certificate.
CCM is in Limited AvailabilityContact your Akamai account representative to have this feature added to your contract.
Before you begin
- In Property Manager, create a brand new property or edit an existing one.
- In CCM, create, sign, and upload a certificate or certificate lineage to which you want to bind your hostname(s).
- Make sure to activate any new certificates or certificate lineages in CCM to both the staging and production networks. Once activated, you can bind them to your hostnames in Property Manager.
- If you create a new version of a certificate lineage, you need to activate it to either the staging or production network before you can select it for hostname binding in Property Manager.
Access Requirements
- Property Manager: Access to modify property configurations.
- Cloud Certificate Manager: Access to the product.
- CCM certificates and certificate lineages: View and bind access to CCM certificates.
- Certificate Authority (CA) sets: Access to Mutual Edge Truststore for mTLS configuration.
- EdgeGrid authentication: API access.
How to
- From the Property Manager Editor, in the Property Hostnames panel, click +Hostnames>Add Hostname(s).
- In the Add Hostname(s) field, enter the hostnames you want to use and click Next. The names don't need to contain
https://, just the domain.
You can add multiple hostnames by pasting them into the field. When adding multiple hostnames, each value needs to be separated by a space or comma, or contained on separate lines. Duplicate names are skipped.
- Under Domain And Certificate Security, select the CCM (Third party) option to use a certificate or certificate lineage previously created in Cloud Certificate Manager.
- Choose a certificate from the Select certificate dropdown. To view available certificate lineages, enable the Filter to show active certificate lineages toggle. If the certificate or certificate lineage doesn't appear in the list after refreshing it, verify group permissions for certificate access, ensure it's marked
READY_FOR_USEorACTIVE, and make sure Cloud Certificate Manager access is enabled for your account.
At this step, you can also create and activate a new certificate or certificate lineage in CCM. See Create a new certificate or certificate lineage in the Cloud Certificate Manager documentation.
- If not selecting a certificate lineage, choose at least one RSA or one ECDSA certificate. You can also choose certificates of both types.
- Optional: To use the mTLS authentication, turn on the Enable Mutual Authentication (mTLS) switch in the Mutual Authentication section after selecting your certificate(s). This displays authentication options. Select the CA set and, if needed, toggle the switches to enable:
- Sending a Certificate Authority (CA) list to the clients.
- Online Certificate Status Protocol (OCSP) for enhanced security.
Akamai validates that the CA set selected in the mTLS section is compatible with the CA set configured in the Enforce mTLS settings behavior. Both the CA set and the associated OCSP settings must match.
- Optional: You can customize your TLS security preferences in the TLS Settings section. Enable the Override TLS Settings switch to manage:
- Cipher profile
- Disallowed TLS versions
- Online certificate status protocol (OSCP) stapling
- FIPS mode
CCM certificates are provisioned with TLS 1.2 and TLS 1.3 by default, using the
ak-akamai-2020q1andak-akamai-2020q1-without-chachapoly1305cipher profiles.
- Before you can activate your hostname, you need to prove ownership of your domain if you haven’t done so already. You can continue with the recommended DNS CNAME domain validation method or decide to use alternative methods like TXT or HTTP.
- Click Next to configure your Mapping Solution settings. Choose either Standard (default) or Edge IP Binding. When making your selection, consider the following:
- Are you using Adaptive Media Delivery or Download Delivery? See What is Use Case-based Edge Mapping?
- If you have Edge IP Binding on your contract, you can enable it here. See What is Edge IP Binding?
- Click Next to configure your edge hostnames.
- Select the checkboxes next to property hostnames you want to configure edge hostnames for. You can apply your edge hostname settings to multiple property hostnames at the same time. You can either configure separate edge hostnames for each property hostname, or have property hostnames with CCM certificates share one common edge hostname.
- Create. With this option selected, you can define a fully custom edge hostname and select a different domain.
- Select existing. Select this option if you want to associate your property hostname with an existing edge hostname. For geo-partitioned CCM certificates, the list only shows edge hostnames that have the same delivery policy. Delivery policies keep edge traffic within a specific geographical region. For more details, see our Delivery Policy Manager documentation.
- Custom. Select this option to manually input a CNAME target to be used in the association. Contact your account representative for further details on the proper use of this field, and whether it applies to your environment configuration.
- If applicable, select the protocol version you want to advertise through HTTPS Service Binding.
- Click Submit.
- Review the information in the Success window and apply its instructions as required. Click Close.
You can view all details for hostnames in the Property Hostnames panel by expanding their corresponding rows.
Switch between certificate types
Akamai supports switching between certificate types for existing hostnames. You can switch certificate types in Property Manager by navigating to an editable property version and clicking Edit under hostname actions.
The following rules apply when switching from one certificate type to another:
| Switch between the same certificate type. | Always supported, including switching between Standard TLS and Enhanced TLS. Example: CCM (Standard TLS) to CCM (Enhanced TLS) |
| Switch between different certificate types. | Generally supported. See Exceptions. Example: CCM (Enhanced TLS) to CPS (Enhanced TLS) |
| Switch to or from CCM certificates. | Generally supported. See Exceptions. Example: Default DV (Standard TLS) to CCM (Standard TLS) |
Exceptions
The following scenarios for switching to and from CCM certificates are not currently supported:
- CCM (Standard TLS) to CPS (Enhanced TLS)
- CCM (Enhanced TLS) to CPS (Standard TLS)
- CCM (Standard TLS) to Default DV (Enhanced TLS)
- CCM (Enhanced TLS) to Default DV (Standard TLS)
- Default DV (Standard TLS) to CCM (Enhanced TLS)
- Default DV (Enhanced TLS) to CCM (Standard TLS)
Updated 13 days ago
