Add a hostname with a CCM certificate (Limited Availability)

Create and provision a Cloud Certificate Manager (CCM) certificate when you add a hostname to a property to easily secure client request.

Property Manager enables you to bind CCM certificates to hostnames, configure mutual TLS (mTLS), and deploy secure configurations across Akamai's network.

📘

CCM certificate is in Limited Availability

To have this feature added to your contract, contact your Akamai representative.

Before you begin

In Property Manager, create a brand new property or edit an existing one.

Access Requirements

  • Property Manager: Access to modify property configurations.
  • Cloud Certificate Manager: Access to the product.
  • CCM certificates: View and bind access to CCM certificates.
  • CA sets: Access to Mutual Edge Truststore for mTLS configuration.
  • EdgeGrid authentication: API access.

How to

  1. In the Property Manager Editor, in the Property Hostnames panel, click +Hostnames>Add Hostname(s).
  2. In the Add Hostname(s) field, enter the hostnames you want to use and click Next. The names don't need to contain https://, just the domain.
📘

You can add multiple hostnames by pasting them into the field. If you do, each value needs to be separated by a space or comma, or contained on separate lines. Duplicate names are skipped.

  1. Select the CCM (Third party) option to use the certificate you previously created in Cloud Certificate Manager. If the Cloud Certificate Manager certificate doesn't appear in the list after refreshing it, verify group permissions for certificate access, ensure the certificate is READY_FOR_USE or ACTIVE, and make sure the Cloud Certificate Manager access is enabled for your account.
📘

You can also create a new certificate in Cloud Certificate Manager. Click Create a new certificate in CCM. See Create new certificate in the Cloud Certificate Manager documentation.

  1. Choose at least one RSA or one ECDSA certificate. You can also choose certificates of both types.
  2. Optional: To use the mTLS authentication toggle the Enable Mutual Authentication (mTLS) switch in the Mutual Authentication section. It shows the authentication options. Select the CA set and, if needed, toggle the switches to enable:
    • Sending a Certificate Authority (CA) list to the clients.
    • Online Certificate Status Protocol (OCSP) for enhanced security.
📘

Akamai validates that the CA set selected in the mTLS section is compatible with the CA set configured in the Enforce mTLS settings behavior. Both the CA set and the associated OCSP settings must match.

  1. Optional: Enable Override TLS Settings to manage:
    • Cipher profile
    • Disallowed TLS versions
    • Online certificate status protocol (OSCP) stapling
    • FIPS mode
📘

CCM certificates are provisioned with TLS 1.2 and TLS 1.3, using either the ak-akamai-2020q1 or ak-akamai-2020q1-without-chachapoly1305 cipher profiles.

  1. Before you can activate your hostname, you need to prove ownership of your domain if you haven’t done so already. You can continue with the recommended DNS CNAME domain validation method or decide to use alternative methods like TXT or HTTP.
  2. Click Next to configure your Mapping Solution settings. Choose either Standard (default) or Edge IP Binding. When making your selection, consider the following:
  3. Click Next to configure your edge hostnames.
  4. Select the checkboxes next to property hostnames you want to configure edge hostnames for. You can apply your edge hostname settings to multiple property hostnames at the same time. You can either configure separate edge hostnames for each property hostname, or have property hostnames with CCM certificates share one common edge hostname.
    • Create. With this option selected, you can define a fully custom edge hostname and select a different domain.
    • Select existing. Select this option if you want to associate your property hostname with an existing edge hostname. For geo-partitioned CCM certificates, the list only shows edge hostnames that have the same delivery policy. Delivery policies keep edge traffic within a specific geographical region. For more details, see our Delivery Policy Manager documentation.
    • Custom. Select this option to manually input a CNAME target to be used in the association. Contact your account representative for further details on the proper use of this field, and whether it applies to your environment configuration.
  5. If applicable, select the protocol version you want to advertise through HTTPS Service Binding.
  6. Click Submit.
  7. Review the information in the Success window and apply its instructions as required. Click Close.

You can view all details for hostnames in the Property Hostnames panel by expanding their corresponding rows.

Switch between certificate types

Akamai supports switching between certificate types for existing hostnames. You can switch certificate types in Property Manager by navigating to an editable property version and clicking Edit under hostname actions.

The following rules apply when switching from one certificate type to another:

Switch between the same certificate type.

Always supported, including switching between Standard TLS and Enhanced TLS.

Example: CCM (Standard TLS) to CCM (Enhanced TLS)

Switch between different certificate types.

Generally supported. See Exceptions.

Example: CCM (Enhanced TLS) to CPS (Enhanced TLS)

Switch to or from CCM certificates.

Generally supported. See Exceptions.

Example: Default DV (Standard TLS) to CCM (Standard TLS)

Exceptions

The following scenarios for switching to and from CCM certificates are not currently supported:

  • CCM (Standard TLS) to CPS (Enhanced TLS)
  • CCM (Enhanced TLS) to CPS (Standard TLS)
  • CCM (Standard TLS) to Default DV (Enhanced TLS)
  • CCM (Enhanced TLS) to Default DV (Standard TLS)
  • Default DV (Standard TLS) to CCM (Enhanced TLS)
  • Default DV (Enhanced TLS) to CCM (Standard TLS)

Did this page help you?